THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3f6p-5ww8-9rcr (high) — MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

[GHSA] GHSA-3f6p-5ww8-9rcr (high) — MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

medgithub_advisoriesPublished 2026-09-01

GHSA-3f6p-5ww8-9rcr Severity: high CVE: None

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

## Summary

A rogue MySQL server (or MITM) can force mysql2 to send credentials in **plaintext** by requesting an auth switch to `mysql_clear_password`. The driver complies without verifying that TLS is active.

## Details

`mysql_clear_password` is registered as a defau

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-3f6p-5ww8-9rcr