CVE-2026-35237 is a denial-of-service vulnerability affecting Oracle MySQL Server's InnoDB component across versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. The vulnerability allows a high-privileged attacker with network access via multiple protocols to cause the MySQL Server to hang or crash repeatedly, resulting in complete service unavailability. The vulnerability has a CVSS 3.1 Base Score of 4.9 (MEDIUM severity) with a network attack vector and low attack complexity, but requires high privileges to exploit. The attack has no impact on confidentiality or integrity, affecting only availability. The relatively low EPSS score of 0.00034 indicates minimal real-world exploitation likelihood compared to other known vulnerabilities. There is currently no evidence of active exploitation, with the vulnerability absent from the CISA KEV catalog and marked as inactive on threat tracking lists. No public exploit code appears to be widely available, and community attention remains minimal based on the low FAUCET Risk Score of 31.0 out of 100. Organizations should prioritize patching based on their reliance on affected MySQL versions and the presence of high-privileged database users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.45CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.8CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.6.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MySQL vulnerabilities
Jun 2, 2026Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Apr 14, 2026