CVE-2026-107382
Awaiting Analysis Awaiting Analysis - Queue

MariaDB Connector/Node.js Denial of Service via TLS Fingerprint Validation

Vulnerability report for CVE-2026-107382, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mariadb-corporation mariadb-connector-nodejs >= 3.3.0, < 3.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects MariaDB Connector/Node.js versions 3.3.0 to 3.5.3. It occurs during zero-configuration TLS fingerprint validation when using Ed25519 password authentication. The issue involves an undefined seed identifier in the Ed25519PasswordAuth.hash() method, causing a ReferenceError that terminates the client process under default Node.js behavior, leading to denial of service.

Detection Guidance

Check MariaDB Connector/Node.js version with npm list mariadb. If version is between 3.3.0 and 3.5.3, the system is vulnerable. Monitor for unexpected process terminations during ed25519 authentication with SSL enabled.

Impact Analysis

If exploited, this vulnerability can cause your Node.js application to crash unexpectedly when connecting to a MariaDB server over TCP with TLS enabled. This results in a denial of service, interrupting database operations and potentially affecting application availability.

Compliance Impact

This vulnerability primarily impacts availability by causing denial of service through process termination during TLS handshake with ed25519 authentication. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, repeated denial of service could disrupt access to personal or health data, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade to MariaDB Connector/Node.js version 3.5.4 or later. Alternatively, provide server CA certificate to client, disable certificate validation by setting rejectUnauthorized to false, or switch to a different authentication plugin.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107382. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart