MySQL Server Vulnerability in Oracle MySQL Affects Multiple Versions
CVE-2025-53054

5.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-53054?

A recently identified vulnerability in Oracle MySQL Server, particularly within the InnoDB component, permits high-privilege attackers with network access to exploit multiple protocols. This exploitation can lead to unauthorized access to data, including the ability to modify, insert, or delete information. Furthermore, successful exploitation can cause repeatable crashes or hangs of the MySQL Server, ultimately resulting in denial of service incidents. The affected versions include 8.0.0 through 8.0.43, 8.4.0 through 8.4.6, and 9.0.0 through 9.4.0.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.43

MySQL Server 8.4.0 <= 8.4.6

MySQL Server 9.0.0 <= 9.4.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53054 : MySQL Server Vulnerability in Oracle MySQL Affects Multiple Versions