fix(deps): update dependency mysql2 to v3 [security] - #74
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
October 13, 2024 18:51
8d9a005 to
293bcad
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
August 10, 2025 12:40
293bcad to
1cb892b
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
September 25, 2025 14:47
1cb892b to
6f01f24
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
October 23, 2025 07:46
6f01f24 to
64a1d88
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
November 18, 2025 14:04
64a1d88 to
5d1f077
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
December 3, 2025 18:43
5d1f077 to
a2d734c
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
December 31, 2025 14:58
a2d734c to
fccc63b
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
January 8, 2026 20:33
fccc63b to
969da19
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
January 19, 2026 18:28
969da19 to
1327ff0
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
February 2, 2026 17:53
1327ff0 to
dea7e4c
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
2 times, most recently
from
February 17, 2026 16:03
180c412 to
be6ed2a
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
March 5, 2026 15:51
be6ed2a to
4739e1b
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
March 13, 2026 11:04
4739e1b to
d06d4e3
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
2 times, most recently
from
March 30, 2026 22:26
d06d4e3 to
298f9d9
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
2 times, most recently
from
April 27, 2026 21:34
298f9d9 to
cd13b4f
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
May 28, 2026 18:14
cd13b4f to
dc3610b
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
June 11, 2026 18:08
dc3610b to
4da5106
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
2 times, most recently
from
July 16, 2026 15:43
114d0e7 to
b369b3c
Compare
renovate
Bot
force-pushed
the
renovate/npm-mysql2-vulnerability
branch
from
July 20, 2026 21:36
b369b3c to
b885414
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.3.2→^3.0.0mysql2 cache poisoning vulnerability
CVE-2024-21507 / GHSA-mqr2-w7wj-jjgr
More information
Details
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the
keyFromFieldsfunction, resulting in cache poisoning. An attacker can inject a colon:character within a value of the attacker-crafted key.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 Remote Code Execution (RCE) via the readCodeFor function
CVE-2024-21508 / GHSA-fpw7-j2hg-69v5
More information
Details
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the
readCodeForfunction due to improper validation of thesupportBigNumbersandbigNumberStringsvalues.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 vulnerable to Prototype Poisoning
CVE-2024-21509 / GHSA-49j4-86m8-q2jw
More information
Details
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through
parserFnintext_parser.jsandbinary_parser.js.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
MySQL2 for Node Arbitrary Code Injection
CVE-2024-21511 / GHSA-4rch-2fh8-94vw
More information
Details
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 vulnerable to Prototype Pollution
CVE-2024-21512 / GHSA-pmh2-wpjm-fj45
More information
Details
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
sidorares/node-mysql2 (mysql2)
v3.9.8Compare Source
Bug Fixes
jonServerPublicKeytoonServerPublicKey(#2699) (8b5f691)v3.9.7Compare Source
Bug Fixes
v3.9.6Compare Source
Bug Fixes
v3.9.5Compare Source
Bug Fixes
v3.9.4Compare Source
Bug Fixes
v3.9.3Compare Source
Bug Fixes
v3.9.2Compare Source
Bug Fixes
v3.9.1Compare Source
Bug Fixes
v3.9.0Compare Source
Features
executemethod (#2398) (baaa92a)v3.8.0Compare Source
Features
Bug Fixes
for await(#2389) (af47148)v3.7.1Compare Source
Bug Fixes
v3.7.0Compare Source
Features
v3.6.5Compare Source
Bug Fixes
v3.6.4Compare Source
Bug Fixes
ConnectionOptions(#2288) (5cd7639)v3.6.3Compare Source
Bug Fixes
v3.6.2Compare Source
Bug Fixes
v3.6.1Compare Source
Bug Fixes
v3.6.0Compare Source
Features
infileStreamFactoryoption (#2159) (5bed0f8)v3.5.2Compare Source
Bug Fixes
v3.5.1Compare Source
Bug Fixes
ResultSetHeader[]toqueryandexecute(f649486)v3.5.0Compare Source
Features
v3.4.5Compare Source
Bug Fixes
v3.4.4Compare Source
Bug Fixes
ProcedureCallPackettoexecuteoverloads (3566ef7)ProcedureCallPackettoqueryoverloads (352c3bc)ProcedureCallPacketto promise-basedexecuteoverloads (8292416)ProcedureCallPacketto promise-basedqueryoverloads (0f31a41)ProcedureCallPackettypings (09ad1d2)v3.4.3Compare Source
Bug Fixes
v3.4.2Compare Source
Bug Fixes
v3.4.1Compare Source
Bug Fixes
createPooluri overload (98623dd)PoolClustertypings (3902ca6)PoolClustertypings (7f38496)parserCacheinpromise.js(7f35cf5)promise.js(4ce2c70)Typesconstant (86655ec)Charsetsconstants (01f77a0)CharsetToEncodingconstants (609229a)parserCache(891a523)Typesconstant (04601dd)Charsetsconstants (51c4196)v3.4.0Compare Source
Features
v3.3.5Compare Source
Bug Fixes
createPoolpromiseasPromisePool(#2060) (ff3c36c)v3.3.4Compare Source
Bug Fixes
PromisePoolConnectionimport name (76db54a)releaseConnectiontypes and promise (4aac9d6)v3.3.3Compare Source
Bug Fixes
v3.3.2Compare Source
Bug Fixes
v3.3.1Compare Source
Bug Fixes
v3.3.0Compare Source
Features
v3.2.4Compare Source
Bug Fixes
v3.2.3Compare Source
Bug Fixes
v3.2.2Compare Source
Bug Fixes
ConnectionOptionsconflict betweenmysqlandmysql/promise(#1955) (eca8bda)v3.2.1Compare Source
Bug Fixes
v3.2.0Compare Source
Features
v3.1.2Compare Source
Bug Fixes
lru-cachereset method to clear (114f266)v3.1.1Compare Source
Bug Fixes
v3.1.0Compare Source
Features
Bug Fixes
v3.0.1Compare Source
Miscellaneous Chores
v3.0.0Compare Source
lru-cachedependency, allowing it do dedupe and be shared between mysql2 and named-placeholders - #1711, mysqljs/named-placeholders#19chaiandmochamoved to devDependencies #1774TCP_NODELAYflag enabled, avoiding long connect timeout in some scenarios #1751Miscellaneous Chores
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.