CVE-2026-34271
MySQL vulnerability analysis and mitigation

Overview

CVE-2026-34271 is a denial-of-service vulnerability in the MySQL Server's Group Replication Plugin, classified as Uncontrolled Resource Consumption (CWE-400). It affects Oracle MySQL Server versions 8.0.0–8.0.45, 8.4.0–8.4.8, and 9.0.0–9.6.0. The vulnerability was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update (CPU), with the CVE reported by Pavel Kohout of Aisle Research. It carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Apr 2026, GitHub Advisory).

Technical details

The root cause is improper control of resource allocation (CWE-400) within MySQL Server's Group Replication Plugin, which can be triggered by a low-privileged, authenticated attacker over the network using multiple protocols. The attack requires no user interaction and has low complexity, making it straightforward to exploit once valid credentials are obtained. Successful exploitation causes the MySQL Server to hang or crash repeatedly, resulting in a complete denial of service. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle CPU Apr 2026, GitHub Advisory).

Impact

Exploitation of this vulnerability results exclusively in an availability impact — specifically, the ability to cause a hang or frequently repeatable crash (complete denial of service) of the MySQL Server. There is no confidentiality or integrity impact. Affected deployments include any MySQL Server instance running the Group Replication Plugin within the vulnerable version ranges, which could disrupt database availability for applications relying on MySQL replication clusters (Oracle CPU Apr 2026).

Exploitability

There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time, according to available threat intelligence (GitHub Advisory). The EPSS score is approximately 0.04% (14th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys (ID: 20573) and Nessus (IDs: 309946, 316818, 318655, 318854, 319583, 320435), enabling scanner-based identification of vulnerable systems.

Mitigation and workarounds

Oracle has released patches for this vulnerability as part of the April 2026 Critical Patch Update. Administrators should upgrade MySQL Server to versions beyond 8.0.45, 8.4.8, and 9.6.0 respectively (i.e., the next patched release in each stream). As a temporary workaround, Oracle recommends blocking network protocols required by the attack at the network perimeter, though this may impact application functionality and is not a long-term solution. Applying the CPU patches as soon as possible is strongly recommended (Oracle CPU Apr 2026). Red Hat has also issued advisories (RHSA-2026:20693, RHSA-2026:23332, RHSA-2026:25052) for affected distributions.

Community reactions

The vulnerability was credited to Pavel Kohout of Aisle Research in Oracle's April 2026 CPU advisory. No notable independent researcher commentary, significant social media discussion, or major media coverage specific to this CVE has been identified beyond standard vulnerability tracking and scanner plugin updates (Oracle CPU Apr 2026).

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • mysql8.4-errmsg
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • mysql-shell
NoYesJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • mysql-connector-j
NoYesJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • mariadb
NoYesJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • mysql8.4-errmsg
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management