Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade mysql2 to version 3.23.1 or higher.
mysql2 is a mostly API compatible with mysqljs and supports majority of features.
Affected versions of this package are vulnerable to Data Amplification in the handleCompressedPacket() function of lib/compressed_protocol.js, which calls zlib.inflate(body, ...) without a maxOutputLength option and uses the packet's 3-byte length field only to branch on !== 0. An attacker can exhaust the client's memory and crash the process by returning a single small compressed packet that inflates to gigabytes at a DEFLATE ratio exceeding 1000:1. This requires the application to connect with compress: true, and the attacker to control or compromise the MySQL server endpoint or perform a MitM on a non-TLS connection.