GHSA-rgwj-5xj2-c3m3: MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
(updated )
Denial of Service of the client application (process crash / OOM) — not the database itself. No authentication bypass or data exposure. Requires compress: true plus a malicious/compromised server or MITM position.
References
Code Behaviors & Features
Detect and mitigate GHSA-rgwj-5xj2-c3m3 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →