Impact
The vulnerability is a flaw in the Optimizer component of Oracle MySQL Server and MySQL Cluster that allows a high‑privileged attacker with network access to cause the server to hang or crash, resulting in a denial of multiple network protocols and a loss of availability without affecting confidentiality or integrity.
Affected Systems
Affected are Oracle MySQL Server versions 8.4.0–8.4.10 and 9.7.0–9.7.1, as well as Oracle MySQL Cluster versions 8.0.0–8.4.10 and 9.7.0–9.7.1. The flaw is present in the Optimizer component of both product families.
Risk and Exploitability
CVSS 3.1 score 4.9 denotes a moderate severity focused on availability. EPSS <1% suggests a low likelihood of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the exploit requires high privileges and network access, an attacker who meets these prerequisites can easily disrupt service. The available vector is remote over multiple protocols, so the risk is confined to network‑exposed installations.
OpenCVE Enrichment