CVE-2025-21574

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 17, 2025
CWE ID 400

Summary

CVE-2025-21574 is a vulnerability impacting Oracle MySQL Server versions 8.0.0-8.0.41, 8.4.0-8.4.4, and 9.0.0-9.2.0. This issue, located in the parser component, is classified as easily exploitable and enables a low-privileged attacker with network access to cause a hang or frequent crashes of the MySQL Server via multiple protocols. Successfully exploited attacks could lead to a denial-of-service condition. The Common Vulnerability Scoring System (CVSS) Base Score for this vulnerability is 6.5, with a focus on availability impacts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Mysql Cluster
  • Oracle MySQL Server
  • MySQL

Affected Vendors

  • Oracle