Data Amplification Affecting mysql2 package, versions <3.23.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MYSQL2-19512510
  • published3 Sept 2026
  • disclosed31 Aug 2026
  • creditiaohkut

Introduced: 31 Aug 2026

CVE NOT AVAILABLE CWE-409  (opens in a new tab)

How to fix?

Upgrade mysql2 to version 3.23.1 or higher.

Overview

mysql2 is a mostly API compatible with mysqljs and supports majority of features.

Affected versions of this package are vulnerable to Data Amplification in the handleCompressedPacket() function of lib/compressed_protocol.js, which calls zlib.inflate(body, ...) without a maxOutputLength option and uses the packet's 3-byte length field only to branch on !== 0. An attacker can exhaust the client's memory and crash the process by returning a single small compressed packet that inflates to gigabytes at a DEFLATE ratio exceeding 1000:1. This requires the application to connect with compress: true, and the attacker to control or compromise the MySQL server endpoint or perform a MitM on a non-TLS connection.

CVSS Base Scores

version 4.0
version 3.1