
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34271 is a denial-of-service vulnerability in the MySQL Server's Group Replication Plugin, classified as Uncontrolled Resource Consumption (CWE-400). It affects Oracle MySQL Server versions 8.0.0–8.0.45, 8.4.0–8.4.8, and 9.0.0–9.6.0. The vulnerability was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update (CPU), with the CVE reported by Pavel Kohout of Aisle Research. It carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Apr 2026, GitHub Advisory).
The root cause is improper control of resource allocation (CWE-400) within MySQL Server's Group Replication Plugin, which can be triggered by a low-privileged, authenticated attacker over the network using multiple protocols. The attack requires no user interaction and has low complexity, making it straightforward to exploit once valid credentials are obtained. Successful exploitation causes the MySQL Server to hang or crash repeatedly, resulting in a complete denial of service. No public proof-of-concept or detailed technical write-up has been identified at this time (Oracle CPU Apr 2026, GitHub Advisory).
Exploitation of this vulnerability results exclusively in an availability impact — specifically, the ability to cause a hang or frequently repeatable crash (complete denial of service) of the MySQL Server. There is no confidentiality or integrity impact. Affected deployments include any MySQL Server instance running the Group Replication Plugin within the vulnerable version ranges, which could disrupt database availability for applications relying on MySQL replication clusters (Oracle CPU Apr 2026).
There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time, according to available threat intelligence (GitHub Advisory). The EPSS score is approximately 0.04% (14th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys (ID: 20573) and Nessus (IDs: 309946, 316818, 318655, 318854, 319583, 320435), enabling scanner-based identification of vulnerable systems.
Oracle has released patches for this vulnerability as part of the April 2026 Critical Patch Update. Administrators should upgrade MySQL Server to versions beyond 8.0.45, 8.4.8, and 9.6.0 respectively (i.e., the next patched release in each stream). As a temporary workaround, Oracle recommends blocking network protocols required by the attack at the network perimeter, though this may impact application functionality and is not a long-term solution. Applying the CPU patches as soon as possible is strongly recommended (Oracle CPU Apr 2026). Red Hat has also issued advisories (RHSA-2026:20693, RHSA-2026:23332, RHSA-2026:25052) for affected distributions.
The vulnerability was credited to Pavel Kohout of Aisle Research in Oracle's April 2026 CPU advisory. No notable independent researcher commentary, significant social media discussion, or major media coverage specific to this CVE has been identified beyond standard vulnerability tracking and scanner plugin updates (Oracle CPU Apr 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."