Impact
The vulnerability resides in the Group Replication Plugin of Oracle MySQL Server. It permits a low‑privileged attacker with network access through supported protocols to cause the server to enter a hang or repeatedly crash, abruptly terminating services. No confidential data is disclosed or altered; the effect is limited to availability loss.
Affected Systems
Affected products are Oracle Corporation MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. The issue is confined to the server component that implements Group Replication.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity focused on availability. EPSS information is lacking, and the vulnerability is not listed in CISA KEV, implying a lower but still realistic threat level. An attacker only needs network reach to the MySQL port and does not require elevated privileges, making exploitation relatively straightforward. Successful exploitation results in a denial‑of‑service condition affecting all clients connected to the compromised instance.
OpenCVE Enrichment