VYPR
Medium severity6.5NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026

CVE-2024-21507

CVE-2024-21507

Description

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mysql2npm
< 3.9.33.9.3

Affected products

7

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.