Oracle MySQL InnoDB Denial-of-Service and Data Manipulation Vulnerability

Vulnerability

A vulnerability has been identified in the MySQL Server component of Oracle MySQL, affecting versions 8.0.0 through 8.0.43, 8.4.0 through 8.4.6, and 9.0.0 through 9.4.0. This vulnerability allows a high-privileged attacker with network access to MySQL Server to cause a complete denial-of-service by hanging the server or causing a frequent, repeatable crash. Additionally, the vulnerability permits unauthorized updates, inserts, or deletions of certain accessible data within MySQL Server.

Impact

Exploitation of this vulnerability leads to a complete denial-of-service condition on the MySQL Server, causing it to hang or crash frequently and repeatedly. Furthermore, it allows unauthorized modifications to some of the data accessible on the MySQL Server, including the ability to update, insert, or delete information.

Added: Oct 21, 2025, 9:48 PM
Updated: Oct 21, 2025, 9:48 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.4
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.