Severity
6.5MEDIUMNVD
GHSA8.8OSV9.8OSV7.8OSV5.5OSV5.3OSV4.7CISA7.5CISA7.2
EPSS
0.6%
top 29.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateMar 25

Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector:

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5oracle_corporation/mysql_server8.0.22 and prior
NVDoracle/mysql8.0.08.0.22
Ubuntumbed/mbedtls< 2.8.0-1ubuntu0.1~esm1+3
Ubuntulinux/linux_kernel< 4.4.0-259.293+3

🔴Vulnerability Details

19
OSV
mbedtls vulnerabilities2026-03-25
OSV
linux-azure, linux-azure-4.15 vulnerabilities2026-03-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2026-01-29
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2025-12-15
OSV
linux-aws-fips, linux-fips vulnerabilities2025-12-03

💥Exploits & PoCs

1
Nuclei
Adobe ColdFusion - Arbitrary File Read

📋Vendor Advisories

15
Microsoft
Microsoft Outlook Remote Code Execution Vulnerability2025-12-09
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (jQueryUI) — CVE-2021-411842024-10-15
CISA
Draytek VigorConnect Path Traversal Vulnerability2024-09-03
CISA
Microsoft Exchange Server Information Disclosure Vulnerability2024-08-21
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/Net (.NET Core) — CVE-2021-241122024-07-15

🕵️Threat Intelligence

1
Wiz
Crying Out Cloud - February Newsletter | Wiz2024-02-01

💬Community

4
Bugzilla
CVE-2021-47428 kernel: powerpc/64s: fix program check interrupt emergency stack path2024-05-22
Bugzilla
CVE-2021-47310 kernel: net: ti: fix UAF in tlan_remove_one2024-05-22
Bugzilla
CVE-2021-47408 kernel: netfilter: conntrack: serialize hash resizes and cleanups2024-05-22
Bugzilla
CVE-2021-47013 kernel: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send2024-02-29
CVE-2021-2024 — Improper Resource Locking in Oracle | cvebase