GHSA-3f6p-5ww8-9rcr

    Dashboard / Vulnerabilities / GHSA-3f6p-5ww8-9rcr

    GHSA-3f6p-5ww8-9rcr

    Published: 1 Sept 2026Last Modified: 10 Sept 2026

    Summary: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

    Details: ## Summary A rogue MySQL server (or MITM) can force mysql2 to send credentials in **plaintext** by requesting an auth switch to `mysql_clear_password`. The driver complies without verifying that TLS is active. ## Details `mysql_clear_password` is registered as a default standard plugin in `lib/commands/auth_switch.js` (line 21). When a server sends an AuthSwitchRequest (0xFE) requesting `mysql_clear_password`, the driver executes it without checking for TLS. The plugin (`lib/auth_plugins/mysql_clear_password.js`) returns `Buffer.from(password + '\0')`. Note: `caching_sha2_password` plugin DOES check for SSL before sending cleartext (line 77). But `mysql_clear_password` has no such guard. ## Attack Scenario 1. Attacker operates rogue MySQL server or performs MITM 2. Server advertises `caching_sha2_password` in handshake 3. Client sends hashed auth response 4. Server replies with AuthSwitchRequest to `mysql_clear_password` 5. Client sends password in plaintext 6. Attacker captures plaintext password ## PoC Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request. ## Suggested Fix Remove `mysql_clear_password` from `standardAuthPlugins`, or add a guard requiring TLS/unix socket before allowing cleartext auth. ## Impact - mysql2: 9M weekly downloads - Any application connecting without TLS is vulnerable to credential theft - Cloud environments with untrusted network paths are especially at risk

    Affected packages

    Package

    Name: mysql2

    Purl: pkg:npm/mysql2

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.22.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3f6p-5ww8-9rcr | CVE-DB