CVE-2026-34308 is an unspecified vulnerability in the JSON component of Oracle MySQL Server. It affects MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0. A low-privileged attacker with network access can exploit the flaw through multiple supported protocols to cause a server hang or frequently repeatable crash. The underlying weakness and vulnerable function have not been publicly specified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-34308, a denial-of-service issue in Oracle MySQL Server's JSON component. It contains two files: a README with vulnerability background, affected versions, privilege requirements, and usage examples; and a single Python exploit script, poc_schema_dos.py. The script is the main entry point and uses argparse, json, and subprocess to generate a malicious JSON Schema and pass it to the local mysql client as a SQL command. The exploit capability is straightforward: it builds a schema with a deep linear chain of internal $ref references (default depth 1200), then executes SELECT JSON_SCHEMA_VALID('<schema>', '"x"'); against a target MySQL server. According to the repository, vulnerable servers recurse through the chained references without an effective depth cap, leading to stack exhaustion and causing mysqld to hang or crash. This is an authenticated network attack against the database service, but only low privileges are required; the README explicitly states that a user with only USAGE on *.* can trigger it. Operationally, the script targets a configurable MySQL host, port, username, and password, defaulting to 127.0.0.1:3306 and root with an empty password. It invokes the mysql CLI rather than using a Python database library. It includes basic result handling to distinguish between unsupported $ref behavior, missing JSON_SCHEMA_VALID(), generic query failure, and likely crash conditions inferred from timeout/connection behavior. Because it delivers an actual crash-inducing query rather than merely checking for exposure, this is a real exploit PoC rather than a detection-only script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.