CVE-2025-21588

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21588
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21588.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-21588
Related
Published
2025-04-15T21:15:54Z
Modified
2025-04-19T03:28:43.073162Z
Downstream
Summary
[none]
Details

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

References

Affected packages

Git / github.com/mysql/mysql-server

Affected ranges

Affected versions

mysql-8.*

mysql-8.0.36
mysql-8.0.37
mysql-8.0.38
mysql-8.0.39
mysql-8.0.40
mysql-8.4.0
mysql-8.4.1
mysql-8.4.2
mysql-8.4.3
mysql-8.4.4

mysql-cluster-7.*

mysql-cluster-7.5.34
mysql-cluster-7.5.35
mysql-cluster-7.5.36
mysql-cluster-7.6.30
mysql-cluster-7.6.31
mysql-cluster-7.6.32

mysql-cluster-8.*

mysql-cluster-8.0.36
mysql-cluster-8.0.37
mysql-cluster-8.0.38
mysql-cluster-8.0.39
mysql-cluster-8.0.40
mysql-cluster-8.4.0
mysql-cluster-8.4.1
mysql-cluster-8.4.2
mysql-cluster-8.4.3
mysql-cluster-8.4.4