CVE-2026-34271 is a denial-of-service vulnerability in Oracle MySQL Server's Group Replication Plugin that affects versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. The flaw allows a low-privileged attacker with network access to cause the MySQL Server to hang or crash repeatedly, completely disrupting availability. This vulnerability is easily exploitable and can be triggered through multiple network protocols without user interaction. The vulnerability carries a CVSS 3.1 base score of 6.5 (Medium severity), with a network-based attack vector requiring low privileges and minimal complexity. The attack has no impact on confidentiality or integrity but results in high availability impact through complete denial of service. The corresponding CVSS vector reflects these characteristics: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and its EPSS score of 0.0004 indicates minimal likelihood of future exploitation compared to other disclosed CVEs. Community attention appears limited at this time, though the medium severity rating and ease of exploitation warrant timely patching of affected MySQL instances.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026