CVE-2026-34303
published 2026-04-21CVE-2026-34303: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.30%
22.3th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql_8.0 | mysql | — | — |
| mysql_8.4 | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql_server | 8.0.0 – 8.0.45 | — |
| oracle | mysql_server | 8.4.0 – 8.4.8 | — |
| oracle | mysql_server | 9.0.0 – 9.6.0 | — |
| oracle_corporation | mysql_server | 8.0.0 – 8.0.45 | — |
| oracle_corporation | mysql_server | 8.4.0 – 8.4.8 | — |
| oracle_corporation | mysql_server | 9.0.0 – 9.6.0 | — |
| ubuntu | mysql-8.0 | — | — |
| ubuntu | mysql-8.4 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle MySQL Server up to 8.0.45/8.4.8/9.6.0 Optimizer denial of service (Nessus ID 316818)
vuldb·2026-05-28·CVSS 6.5
CVE-2026-34303 [MEDIUM] Oracle MySQL Server up to 8.0.45/8.4.8/9.6.0 Optimizer denial of service (Nessus ID 316818)
A vulnerability was found in Oracle MySQL Server up to 8.0.45/8.4.8/9.6.0. It has been classified as problematic. This affects an unknown function of the component Optimizer. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-34303. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-565v-jcgw-g7vh: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
ghsa_unreviewed·2026-04-21
CVE-2026-34303 [MEDIUM] CWE-400 GHSA-565v-jcgw-g7vh: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2026-06-03
CVE-2026-22005 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
USN-8363-1 fixed several vulnerabilities in MySQL. This update
provides the corresponding fixes for MySQL on Ubuntu 20.04 LTS.
Original advisory details:
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html
https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2026-06-02
CVE-2026-22015 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html
https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-9.html
https://www.oracle.com/security-alerts/cpuapr2026.html
Instructions: This update uses a new upstream release, which includes additional bug
fixes.
Red Hat
mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
vendor_redhat·2026-04-21·CVSS 6.5
CVE-2026-34303 [MEDIUM] CWE-770 mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
Oracle CPU describes the issue as following: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.
Package: mysql8.4 (Red Hat Enterprise Linux 10) - Affected
Package: mysql (Red Hat Enterprise Linux 6) -
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-21998 CVE-2026-22001 CVE-2026-22002 CVE-2026-22004 CVE-2026-22005 CVE-2026-22009 CVE-2026-22015 CVE-2026-22017 CVE-2026-34270 CVE-2026-34271 CVE-2026-34276 CVE-2026-34303 CVE-2026-34304 CVE-2
bugzilla·2026-04-23·CVSS 4.9
CVE-2026-21998 [MEDIUM] CVE-2026-21998 CVE-2026-22001 CVE-2026-22002 CVE-2026-22004 CVE-2026-22005 CVE-2026-22009 CVE-2026-22015 CVE-2026-22017 CVE-2026-34270 CVE-2026-34271 CVE-2026-34276 CVE-2026-34303 CVE-2026-34304 CVE-2
CVE-2026-21998 CVE-2026-22001 CVE-2026-22002 CVE-2026-22004 CVE-2026-22005 CVE-2026-22009 CVE-2026-22015 CVE-2026-22017 CVE-2026-34270 CVE-2026-34271 CVE-2026-34276 CVE-2026-34303 CVE-2026-34304 CVE-2026-34308 ... mysql8.4: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34303 mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
bugzilla·2026-04-21·CVSS 6.5
CVE-2026-34303 [MEDIUM] CVE-2026-34303 mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
CVE-2026-34303 mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
2026-04-21
Published