Impact
The vulnerability resides in Oracle’s MySQL Connector/ODBC 26.7.0. It allows an attacker with low privileges but network access to send specially crafted traffic through supported protocols, causing the connector to hang or repeatedly crash. The impact is a complete denial of service affecting applications that rely on the connector for database access.
Affected Systems
Oracle Corporation’s MySQL Connector/ODBC version 26.7.0 is the affected product.
Risk and Exploitability
The base CVSS score of 6.5 indicates moderate severity for availability. The EPSS score of < 1 % suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the ease of remote exploitation for low‑privilege attackers and the potential to disrupt services exposed over a network create a non‑negligible risk for organizations that run the connector in accessible environments.
OpenCVE Enrichment