Impact
A flaw in MySQL Server and MySQL Cluster JSON parsing can lead to uncontrolled resource consumption and excessive memory allocation. When an attacker feeds the database with specially crafted JSON data, the server can consume large amounts of CPU and memory, ultimately hanging or repeatedly crashing. This results in a complete denial of service while no data confidentiality or integrity is compromised. The weakness is catalogued as CWE‑400 and CWE‑770.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster versions 9.7.0 through 9.7.1 are affected. No other releases are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a medium severity availability impact. An EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not included in the CISA KEV catalog. Attackers with low privileges and network access over supported protocols can exploit the flaw, triggering a crash or hang without requiring elevated permissions.
OpenCVE Enrichment