Impact
The vulnerability resides in the Optimizer component of Oracle MySQL Server, allowing an attacker with low privileges and network access to cause the server to hang or crash repeatedly. This results in a denial of service, affecting only availability with no impact on confidentiality or integrity.
Affected Systems
Affected versions are Oracle MySQL Server 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. The vendor is Oracle Corporation. The issue applies to any installation configured to accept network connections through standard MySQL protocols, such as TCP ports 3306 and 33060.
Risk and Exploitability
The risk level is moderate because the exploit requires only network reachability and low‑privileged access, but it can lead to a complete service disruption. This is reflected in a CVSS base score of 6.5, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower documented exploitation prevalence. An attacker can repeatedly trigger a crash by sending specially crafted queries that exploit the optimizer, leading to downtime until the service is restarted or the patch is applied.
OpenCVE Enrichment