CVE-2026-22017 is a denial-of-service vulnerability in Oracle MySQL Server's Optimizer component affecting versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. The flaw allows low-privileged attackers with network access to trigger server hangs or crashes through multiple protocols, completely disabling the affected MySQL instance. This represents an availability-focused threat rather than a confidentiality or integrity concern. The vulnerability carries a CVSS 3.1 base score of 6.5 (Medium severity) with a network attack vector and low complexity, requiring only low-level privileges and no user interaction. The attack is easily exploitable, making it accessible to relatively unsophisticated threat actors who can establish network connectivity to MySQL servers. The primary impact is complete denial of service through frequent, repeatable crashes. From an exploitation standpoint, CVE-2026-22017 does not appear to be actively exploited in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and maintains an EPSS score of 0.0004, indicating minimal real-world exploitation activity to date. Current community attention appears limited, suggesting this remains a lower-priority threat compared to actively exploited vulnerabilities, though organizations running affected MySQL versions should still apply patches to prevent potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026