{"id":"CVE-2024-21507","aliases":["GHSA-mqr2-w7wj-jjgr"],"url":"https://o3.security/vulnerability/CVE-2024-21507","summary":"mysql2 cache poisoning vulnerability","details":"Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.","published":"2024-04-10T05:00:01.727Z","modified":"2026-07-15T01:49:01.919893614Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mysql2","fixedVersion":"3.9.3"}],"fix":{"url":"https://github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818","label":"sidorares/node-mysql2@0d54b0c"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591300"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21507.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21507"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818"},{"type":"FIX","url":"https://github.com/sidorares/node-mysql2/pull/2424"},{"type":"ARTICLE","url":"https://blog.slonser.info/posts/mysql2-attacker-configuration/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:01.919893614Z"}}