mysql: Optimizer unspecified vulnerability (CPU Apr 2026)
Published Apr 21, 2026
4.9
MEDIUMCVSS 3.1
EPSS 0.45%
Description
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected products
-
- Version 8.0.0StatusaffectedConstraints<=8.0.45
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | MySQL Server | n/a |
|
- ≥ 8.0.0 · ≤ 8.0.45
No data.
Red Hat Enterprise Linux 8
mysql:8.0-8100020260609092222.489197e6
Fixed · RHSA-2026:25919
Red Hat Enterprise Linux 9
mysql-0:8.0.46-1.el9_8
Fixed · RHSA-2026:23332
Red Hat Enterprise Linux 10
mysql8.4
Affected
Red Hat Enterprise Linux 6
mysql
Not affected
Red Hat Enterprise Linux 8
mysql:8.4/mysql
Affected
Red Hat Enterprise Linux 9
mysql:8.4/mysql
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | mysql:8.0-8100020260609092222.489197e6 | Fixed | RHSA-2026:25919 |
| Red Hat Enterprise Linux 9 | mysql-0:8.0.46-1.el9_8 | Fixed | RHSA-2026:23332 |
| Red Hat Enterprise Linux 10 | mysql8.4 | Affected | n/a |
| Red Hat Enterprise Linux 6 | mysql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mysql:8.4/mysql | Affected | n/a |
| Red Hat Enterprise Linux 9 | mysql:8.4/mysql | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-34278 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460368 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-34278
- https://www.cve.org/CVERecord?id=CVE-2026-34278
- https://www.oracle.com/security-alerts/cpuapr2026.html vendor-advisoryVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-34278 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460368 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-34278 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-34278 | ||
| https://www.oracle.com/security-alerts/cpuapr2026.html | vendor-advisoryVendor Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL |
Change history (0)
No recorded changes yet.