CVE-2026-22004 is a denial-of-service vulnerability affecting Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0, specifically within the InnoDB component. The vulnerability allows a high-privileged attacker with network access via multiple protocols to trigger a hang or repetitive crash of the MySQL Server, resulting in complete service unavailability. The vulnerability presents a medium-severity risk with a CVSS 3.1 base score of 4.9. It requires network access and high-level privileges but is easily exploitable with low attack complexity and no user interaction needed. The impact is limited to availability, with no confidentiality or integrity compromise possible. This vulnerability currently shows minimal exploitation activity in the wild, with an extremely low EPSS score of 0.0004 and no listing on the Known Exploited Vulnerabilities catalog. The FAUCET Risk Score of 31.0/100 and inactive status on threat intelligence hot lists indicate low community attention and no publicly available proof-of-concept exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026