CVE-2024-21512
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L/E:P
- EPSS probability
- 3.11%
- CWE
- CWE-1321
- Published
- 2024-05-29
- Last modified
- 2026-03-13
Affected products
- n/a mysql2
- n/a org.webjars.npm:mysql2
Weakness type
Related vulnerabilities
- CVE-2011-10019 — Spreecommerce < 0.60.2 Search Parameter RCE
- CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-32621 — Apollo Federation has prototype pollution via incomplete key sanitization
- CVE-2025-25015 — Kibana arbitrary code execution via prototype pollution
- CVE-2026-33994 — Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
- CVE-2026-21854 — Tarkov Data Manager Authentication Bypass vulnerability
- CVE-2026-33696 — n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE
- CVE-2026-27212 — Swiper has a Prototype Pollution Vulnerability