Impact
Vulnerability in the MySQL Server and MySQL Cluster components that parse JSON input can cause a complete denial of service when an attacker sends specially crafted data. The flaw leads to a server‑side crash or hang, resulting in loss of availability for any application relying on MySQL. No confidentiality or integrity impact is disclosed in the available information.
Affected Systems
The affected products are Oracle MySQL Server and Oracle MySQL Cluster, specifically the 9.7.0 to 9.7.1 releases. Other versions are not listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a medium severity availability impact. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation at the time of analysis. The vulnerability is not included in CISA’s KEV catalog, and there is no known public exploit referenced. Attackers need only low privileges and network access over supported protocols to trigger the crash.
OpenCVE Enrichment