Insufficiently Protected Credentials Affecting org.webjars.npm:mysql2 package, versions [,3.22.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-19498546
  • published14 Sept 2026
  • disclosed1 Sept 2026
  • creditUnknown

Introduced: 1 Sep 2026

New CVE NOT AVAILABLE CWE-522  (opens in a new tab)

How to fix?

Upgrade org.webjars.npm:mysql2 to version 3.22.0 or higher.

Overview

org.webjars.npm:mysql2 is a mostly API compatible with mysqljs and supports majority of features.

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the authSwitchRequest handling in lib/commands/auth_switch.js and the direct auth path in lib/commands/client_handshake.js. An attacker controlling a MySQL server or intercepting the connection can request mysql_clear_password during authentication and force the client to send the password in plaintext. This leaks user credentials over the network, letting the attacker capture login secrets and compromise accounts when the connection is not protected by TLS.

CVSS Base Scores

version 4.0
version 3.1