← Back to browse · API

CVE-2024-21508

Severity
CRITICAL
CVSS
9.8
EPSS
0.02554
Risk score
40.09
CISA KEV
No
PoC
No
Published
2024-04-11
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-1197, GHSA-FPW7-J2HG-69V5
Products
n/a:mysql2, n/a:mysql2 0 <3.9.4
Sources
euvd EUVD-2024-1197

Description

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

References