GHSA-3f6p-5ww8-9rcr
## Summary A rogue MySQL server (or MITM) can force mysql2 to send credentials in **plaintext** by requesting an auth switch to `mysql_clear_password`. The driver complies without verifying that TLS is active. ## Details `mysql_clear_password` is registered as a default standard plugin in `lib/commands/auth_switch.js` (line 21). When a server sends an AuthSwitchRequest (0xFE) requesting `mysql_clear_password`, the driver executes it without checking for TLS. The plugin (`lib/auth_plugins/mysql_clear_password.js`) returns `Buffer.from(password + '\0')`. Note: `caching_sha2_password` plugin DOES check for SSL before sending cleartext (line 77). But `mysql_clear_password` has no such guard. ## Attack Scenario 1. Attacker operates rogue MySQL server or performs MITM 2. Server advertises `caching_sha2_password` in handshake 3. Client sends hashed auth response 4. Server replies with AuthSwitchRequest to `mysql_clear_password` 5. Client sends password in plaintext 6. Attacker captures plaintext password ## PoC Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request. ## Suggested Fix Remove `mysql_clear_password` from `standardAuthPlugins`, or add a guard requiring TLS/unix socket before allowing cleartext auth. ## Impact - mysql2: 9M weekly downloads - Any application connecting without TLS is vulnerable to credential theft - Cloud environments with untrusted network paths are especially at risk
Properties
- ghsa_id
- GHSA-3f6p-5ww8-9rcr
- severity
- high
- summary
- MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
- cve_id
- GHSA-3f6p-5ww8-9rcr
- is_ghsa_only
- true
- ghsa_published
- 2026-09-01T16:40:34Z
- source_url
- https://github.com/advisories/GHSA-3f6p-5ww8-9rcr
- ghsa_updated
- 2026-09-01T16:40:35Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph