7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether mysql2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
GHSA-3f6p-5ww8-9rcr
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
MEDIUM 5.9
GHSA-rgwj-5xj2-c3m3
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
MEDIUM 6.5
CVE-2024-21507
mysql2 cache poisoning vulnerability
CRITICAL 9.8
CVE-2024-21508
mysql2 Remote Code Execution (RCE) via the readCodeFor function
MEDIUM 6.5
CVE-2024-21509
mysql2 vulnerable to Prototype Poisoning
CRITICAL 9.8
CVE-2024-21511
MySQL2 for Node Arbitrary Code Injection
HIGH 8.2
CVE-2024-21512
mysql2 vulnerable to Prototype Pollution
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes