Impact
The vulnerability is in the JSON handling component of MySQL Server and MySQL Cluster and allows a low privileged attacker with network access to send crafted JSON data that causes the server processes to hang or crash repeatedly, resulting in a complete denial of service. The weakness is an uncontrolled resource consumption or input validation issue (CWE-400) that impacts the availability of the database services without affecting confidentiality or integrity.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity with a pure availability impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve remote access over supported networking protocols, with an attacker requiring only low privileges to submit malicious JSON requests that trigger the crash.
OpenCVE Enrichment