Skip to content

Update mysql2 dependency version to 3.23.1 - #4086

Closed
hack-313-ip wants to merge 1 commit into
ory:mainfrom
hack-313-ip:main
Closed

hack-313-ip wants to merge 1 commit into
ory:mainfrom
hack-313-ip:main

Conversation

@hack-313-ip

Copy link
Copy Markdown

Title: Vulnerable dependency mysql2@3.22.5 (Data Amplification / DoS)

Hi team,

In npm/package.json the project depends on:
"mysql2": "3.22.5"

This version is affected by a High severity Data Amplification vulnerability:

  • Snyk: SNYK-JS-MYSQL2-19512510
  • CWE-409
  • CVSS: 8.2
  • Fixed in: mysql2@3.23.1

The issue is in handleCompressedPacket() (lib/compressed_protocol.js) which calls zlib.inflate without a maxOutputLength limit. A malicious or compromised MySQL server (or MitM on a non-TLS connection) can send a small compressed packet that expands to a very large size, causing memory exhaustion and process crash when compress: true is used.

Recommendation: Upgrade mysql2 to 3.23.1 or later.

Thanks.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 99dc3b75-b371-4515-bfd5-ad5db5e568a0

📥 Commits

Reviewing files that changed from the base of the PR and between e13ed65 and cf96ae7.

📒 Files selected for processing (1)
  • npm/package.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant