Package compatibility
mysql2
Node.js requirements from npm Registry (engines.node) for the mysql2 package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2024-21512GHSA-pmh2-wpjm-fj45
mysql2 vulnerable to Prototype Pollution
- Affected:
- <3.9.8
- Fixed in:
- 3.9.8
- Source:
- OSV source · Advisory
- CVE-2024-21511GHSA-4rch-2fh8-94vw
MySQL2 for Node Arbitrary Code Injection
- Affected:
- <3.9.7
- Fixed in:
- 3.9.7
- Source:
- OSV source · Advisory
- CVE-2024-21508GHSA-fpw7-j2hg-69v5
mysql2 Remote Code Execution (RCE) via the readCodeFor function
- Affected:
- <3.9.4
- Fixed in:
- 3.9.4
- Source:
- OSV source · Advisory
- CVE-2024-21509GHSA-49j4-86m8-q2jw
mysql2 vulnerable to Prototype Poisoning
- Affected:
- <3.9.4
- Fixed in:
- 3.9.4
- Source:
- OSV source · Advisory
- CVE-2024-21507GHSA-mqr2-w7wj-jjgr
mysql2 cache poisoning vulnerability
- Affected:
- <3.9.3
- Fixed in:
- 3.9.3
- Source:
- OSV source · Advisory
