Denial of Service Vulnerability in Oracle MySQL Server
CVE-2025-21581

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists in Oracle MySQL Server affecting versions 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. This weakness allows a high privileged attacker with network access to exploit the server through multiple protocols. The result can be a denial of service, leading to unintentional server hangs or frequent crashes, thereby impacting the availability of the MySQL service.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.41

MySQL Server 8.4.0 <= 8.4.4

MySQL Server 9.0.0 <= 9.2.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.