Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2185530
AlmaLinux
5861
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17153
BellSoft Hardened Containers
744
Bitnami
9224
Chainguard
1020158
CleanStart
3450
CRAN
14
crates.io
2720
Debian
67380
Echo
6542
GHC
3
GIT
106460
GitHub Actions
55
Go
9157
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6203
Maven
6998
MinimOS
142898
npm
228510
NuGet
1860
opam
29
openEuler
8674
openSUSE
14332
OSS-Fuzz
4004
Packagist
7036
Pub
11
PyPI
25079
Red Hat
23056
Rocky Linux
4234
Root
19466
RubyGems
4709
SUSE
23046
SwiftURL
59
TuxCare
9237
Ubuntu
64506
VSCode
21
Wolfi
287393
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rqfv-2mw9-78g2
PyPI/mysql-mcp-server
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
11 Sep
Fix available
Severity - 10.0 (Critical)
PYSEC-2026-3579
PyPI/mysql-mcp-server
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
04 Aug
Fix available
Severity - 2.1 (Low)
PYSEC-2026-1151
PyPI/apache-airflow-providers-mysql
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1685
PyPI/mysql-connector-python
MySQL Connector/Python connector takeover vulnerability
07 Jul
Fix available
Severity - 7.7 (High)
PYSEC-2026-682
PyPI/mysql-connector-python
MySQL Connectors Privilege Escalation
02 Jul
No fix available
Severity - 3.3 (Low)
PYSEC-2026-683
PyPI/mysql-connector-python
Improper Access Control in MySQL Connector Python
02 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-279
PyPI/apache-airflow-providers-mysql
Command Injection in Apache Airflow and Apache Airflow MySQL Provider
29 Jun
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-217
PyPI/mariadb
See record for full details
12 Jun
No fix available
Severity - 9.8 (Critical)
GHSA-mvq4-39wx-6h5g
PyPI/mysql-mcp-server
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
08 Jun
Fix available
Severity - 2.1 (Low)
GHSA-hhm6-jjf4-6pm3
PyPI/apache-airflow-providers-mysql
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
19 Mar 2025
Fix available
Severity - 5.3 (Medium)
GHSA-hgjp-83m4-h4fj
PyPI/mysql-connector-python
MySQL Connector/Python connector takeover vulnerability
15 Oct 2024
Fix available
Severity - 7.7 (High)
GHSA-c732-xvv8-g94c
PyPI/apache-airflow
PyPI/apache-airflow-providers-mysql
Command Injection in Apache Airflow and Apache Airflow MySQL Provider
21 Jan 2023
Fix available
Severity - 9.8 (Critical)
GHSA-2cf3-g243-hhfx
PyPI/mysql-connector-python
MySQL Connectors Privilege Escalation
13 May 2022
No fix available
Severity - 3.3 (Low)
GHSA-v5rq-w2xm-7g5f
PyPI/mysql-connector-python
Improper Access Control in MySQL Connector Python
13 May 2022
Fix available
Severity - 8.1 (High)
PyPI - OSV