PT-2026-108145 · Mariadb · Mariadb-Connector-Nodejs
CVE-2026-107382
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MariaDB Connector/Node.js versions 3.3.0 through 3.5.3
Description
A denial of service issue exists in the zero-configuration TLS fingerprint-validation path. When the connector validates a server's identity via
Authentication.validateFingerPrint, it calls the Ed25519PasswordAuth.hash() function. This function references a seed identifier that is not in scope, resulting in a synchronous ReferenceError. Because this error occurs within the socket data handler and is not caught, it triggers an uncaught exception that terminates the Node.js client process.This can be triggered by a legitimate server, a malicious server, or a network attacker presenting a self-signed certificate. Exploitation requires a MariaDB server reached over TCP, TLS enabled (via
ssl: true or an ssl object where rejectUnauthorized is not false), a set password, no ssl.ca configured, and the client ed25519 authentication plugin negotiated.Recommendations
Update to version 3.5.4 or later.
As a temporary workaround, provide the server certificate to the client using
ssl: { ca: ... } to enable standard certificate validation.
As a temporary workaround, set ssl: { rejectUnauthorized: false } to enable trust mode.
As a temporary workaround, use an authentication plugin other than client ed25519.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mariadb-Connector-Nodejs