Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).
Conclusion & alert: CVE-2025-21520 is rated Low Risk (14.4/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.28%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.02% | 0.28% | +0.26% |
| 2 | 2026-03-03 | 0.10% | 0.02% | -0.07% |
| 3 | 2025-11-21 | — | 0.10% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.8 | 3.1 | LOW |
|
0.3 | 1.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-21520 not yet assigned priority: Debian including 1 source packages (mysql-8.0), 1 status rows across 1 suites (sid): resolved 1. | https://security-tracker.debian.org/tracker/CVE-2025-21520 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2025-21520 |
ubuntu
|
medium | CVE-2025-21520 medium priority: Ubuntu including 10 source packages (mariadb, mariadb-10.0, …), 77 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 50, not-affected 19, needs-triage 7, ignored 1. | https://ubuntu.com/security/CVE-2025-21520 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| oracle | mysql_cluster | >= 7.6.0, <= 7.6.32 | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| oracle | mysql_cluster | >= 8.0.0, <= 8.0.40 | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| oracle | mysql_cluster | >= 8.4.0, <= 8.4.3 | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| oracle | mysql_cluster | >= 9.0.0, <= 9.1.0 | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| oracle | mysql_server | >= 8.0.0, <= 8.0.40 | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
| oracle | mysql_server | >= 8.4.0, <= 8.4.3 | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
| oracle | mysql_server | >= 9.0.0, <= 9.1.0 | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |