CVE-2026-21952
published 2026-01-20CVE-2026-21952: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable…
PriorityP422medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.34%
25.9th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-8.0 | — | — |
| oracle | mysql_server | 9.0.0 – 9.5.0 | — |
| oracle_corporation | mysql_server | 9.0.0 – 9.5.0 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_oracle4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3xh-936h-7hqm: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser)
ghsa_unreviewed·2026-01-21
CVE-2026-21952 [MEDIUM] CWE-400 GHSA-r3xh-936h-7hqm: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
OSV
CVE-2026-21952: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser)
osv·2026-01-20·CVSS 4.9
CVE-2026-21952 [MEDIUM] CVE-2026-21952: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Red Hat
mysql: Parser unspecified vulnerability (CPU Jan 2026)
vendor_redhat·2026-01-20·CVSS 4.9
CVE-2026-21952 [MEDIUM] mysql: Parser unspecified vulnerability (CPU Jan 2026)
mysql: Parser unspecified vulnerability (CPU Jan 2026)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitab
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Parser — CVE-2026-21952
vendor_oracle·2026-01-15·CVSS 4.9
CVE-2026-21952 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Parser — CVE-2026-21952
Oracle Oracle MySQL Risk Matrix: Server: Parser vulnerability
CVE: CVE-2026-21952
CVSS: 4.9
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Debian
CVE-2026-21952: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pa...
vendor_debian·2026·CVSS 4.9
CVE-2026-21952 [MEDIUM] CVE-2026-21952: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pa...
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21968 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-21968 [MEDIUM] CVE-2026-21968 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21968 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 6.5
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
MySQL
MariaDB Server
Has Public Exploit No
Wiz
CVE-2026-21936 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-21936 [MEDIUM] CVE-2026-21936 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21936 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
MySQL Cluster
Has Public Exploit No
Has CISA KE
Wiz
CVE-2026-21948 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-21948 [MEDIUM] CVE-2026-21948 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21948 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
Rocky Linux
Has Public Exploit No
Ha
Wiz
CVE-2026-21964 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-21964 [MEDIUM] CVE-2026-21964 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21964 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
Rocky Linux
Has Public Exploit N
Wiz
CVE-2026-0994 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-0994 [HIGH] CVE-2026-0994 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0994 :
MySQL vulnerability analysis and mitigation
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.
Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
Source : NVD
## 8.2
Score
Published January 23, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
MySQL
Python
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.2
Expl
Wiz
CVE-2026-21950 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-21950 [HIGH] CVE-2026-21950 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21950 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 6.5
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
MySQL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date
Wiz
CVE-2026-21965 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-21965 [HIGH] CVE-2026-21965 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21965 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).
Source : NVD
## 2.7
Score
Published January 20, 2026
Severity LOW
CNA Score 2.7
Affected Technologies
MySQL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CI
Wiz
CVE-2026-21929 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-21929 [HIGH] CVE-2026-21929 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21929 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 5.3
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
MySQL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date
Wiz
CVE-2026-21952 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-21952 [HIGH] CVE-2026-21952 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21952 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N
Wiz
CVE-2026-21949 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-21949 [HIGH] CVE-2026-21949 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21949 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 6.5
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
MySQL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date
Wiz
CVE-2026-21941 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-21941 [MEDIUM] CVE-2026-21941 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21941 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
Rocky Linux
Has Public Exploit No
Ha
Wiz
CVE-2026-21937 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2026-21937 [MEDIUM] CVE-2026-21937 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21937 :
MySQL vulnerability analysis and mitigation
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Source : NVD
## 4.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
MySQL
Rocky Linux
Has Public Exploit No
Has CISA
2026-01-20
Published