CVE-2026-107383
Awaiting Analysis Awaiting Analysis - Queue

Memory Corruption in MariaDB Connector/Node.js

Vulnerability report for CVE-2026-107383, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mariadb-corporation mariadb-connector-nodejs < 3.2.5
mariadb-corporation mariadb-connector-nodejs >= 3.3.0, < 3.3.4
mariadb-corporation mariadb-connector-nodejs >= 3.4.0, < 3.4.7
mariadb-corporation mariadb-connector-nodejs >= 3.5.0-rc.0, < 3.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MariaDB Connector/Node.js versions before 3.2.5, 3.3.4, 3.4.7, and 3.5.4 have a flaw in GeoJSON Polygon and MultiPolygon binary encoders. The issue occurs when the encoder allocates memory for a buffer based on the length of a ring without verifying if the ring is an array. If the ring is malformed, the buffer may contain uninitialized heap data from Node.js memory, which gets sent to the database via execute() or batch().

Detection Guidance

To detect this vulnerability, check the version of MariaDB Connector/Node.js in your application dependencies. If using npm, run: npm list mariadb-connector-nodejs. Versions before 3.2.5, 3.3.4, 3.4.7, and 3.5.4 are vulnerable.

Impact Analysis

This vulnerability could expose sensitive data such as other users' content, session details, database credentials, or TLS key material. The leaked data may persist in database backups and replicas, potentially affecting multiple systems and users.

Compliance Impact

This vulnerability could lead to unauthorized exposure of personal or sensitive data, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Upgrade MariaDB Connector/Node.js to versions 3.2.5, 3.3.4, 3.4.7, or 3.5.4 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107383. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart