Oracle MySQL Server
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*
- >= 8.0.0, <= 8.0.41
- >= 8.4.0, <= 8.4.4
- >= 9.0.0, <= 9.2.0
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL. This issue affects versions 8.0.0-8.0.41, 8.4.0-8.4.4, and 9.0.0-9.2.0. The vulnerability allows a high-privileged attacker with network access to MySQL Server to cause a complete hang or a frequently repeatable crash, leading to a total denial-of-service condition on the server.
Exploitation of this vulnerability can cause a complete hang or a frequently repeatable crash of the MySQL Server, resulting in a total denial-of-service condition.
Users can apply the security patches provided in the April 2025 Oracle Critical Patch Update to address this vulnerability. Instructions for applying these patches can be found in the MySQL Critical Patch Update documentation available on My Oracle Support.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.