Vulnerability in MySQL Server by Oracle Affecting Thread Pooling Feature
CVE-2025-50100

2.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50100?

A vulnerability exists in the MySQL Server component of Oracle MySQL, specifically related to the thread pooling feature. This issue affects multiple supported versions of the MySQL Server, ranging from 8.0.0 to 9.3.0. An attacker with high privileges and network access through various protocols can exploit this vulnerability, potentially leading to unauthorized actions that may result in a partial denial of service. Oracle has released an advisory addressing this security concern, noting the importance of reviewing current implementations to mitigate any risks.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.42

MySQL Server 8.4.0 <= 8.4.5

MySQL Server 9.0.0 <= 9.3.0

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50100 : Vulnerability in MySQL Server by Oracle Affecting Thread Pooling Feature