mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
Published Apr 21, 2026
4.9
MEDIUMCVSS 3.1
EPSS 0.32%
Description
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected products
-
- Version 8.0.0StatusaffectedConstraints<=8.0.45
- Version 8.4.0StatusaffectedConstraints<=8.4.8
- Version 9.0.0StatusaffectedConstraints<=9.6.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | MySQL Server | n/a |
|
- ≥ 8.0.0 · ≤ 8.0.45
- ≥ 8.4.0 · ≤ 8.4.8
- ≥ 9.0.0 · ≤ 9.6.0
No data.
Red Hat Enterprise Linux 10
mysql8.4-0:8.4.9-1.el10_2
Fixed · RHSA-2026:20693
Red Hat Enterprise Linux 8
mysql:8.0-8100020260609092222.489197e6
Fixed · RHSA-2026:25919
Red Hat Enterprise Linux 8
mysql:8.4-8100020260526091138.489197e6
Fixed · RHSA-2026:26180
Red Hat Enterprise Linux 9
mysql-0:8.0.46-1.el9_8
Fixed · RHSA-2026:23332
Red Hat Enterprise Linux 9
mysql:8.4-9080020260602140041.rhel9
Fixed · RHSA-2026:25052
Red Hat Enterprise Linux 6
mysql
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | mysql8.4-0:8.4.9-1.el10_2 | Fixed | RHSA-2026:20693 |
| Red Hat Enterprise Linux 8 | mysql:8.0-8100020260609092222.489197e6 | Fixed | RHSA-2026:25919 |
| Red Hat Enterprise Linux 8 | mysql:8.4-8100020260526091138.489197e6 | Fixed | RHSA-2026:26180 |
| Red Hat Enterprise Linux 9 | mysql-0:8.0.46-1.el9_8 | Fixed | RHSA-2026:23332 |
| Red Hat Enterprise Linux 9 | mysql:8.4-9080020260602140041.rhel9 | Fixed | RHSA-2026:25052 |
| Red Hat Enterprise Linux 6 | mysql | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-21998 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460312 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-21998
- https://www.cve.org/CVERecord?id=CVE-2026-21998
- https://www.oracle.com/security-alerts/cpuapr2026.html vendor-advisoryVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-21998 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460312 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-21998 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-21998 | ||
| https://www.oracle.com/security-alerts/cpuapr2026.html | vendor-advisoryVendor Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL |
Change history (0)
No recorded changes yet.