PT-2026-108146 · Mariadb · Mariadb-Connector-Nodejs

CVE-2026-107383

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MariaDB Connector/Node.js versions prior to 3.2.5 MariaDB Connector/Node.js versions prior to 3.3.4 MariaDB Connector/Node.js versions prior to 3.4.7 MariaDB Connector/Node.js versions prior to 3.5.4
Description When encoding GeoJSON Polygon and MultiPolygon parameters for the binary protocol, the connector uses Buffer.allocUnsafe() to allocate memory based on the length property of each ring before verifying if the ring is actually an array. If a malformed non-array ring with a numeric length is provided, the connector reserves memory that the writing loop skips. Consequently, the full buffer is sent through the execute() or batch() endpoints, disclosing uninitialized Node.js heap data into the database. This leaked memory may contain sensitive information such as other users' content, session tokens, cookies, database credentials, or TLS key material, which can then persist in backups and replicas. The query() path is not affected as it uses a text encoder.
Recommendations Update MariaDB Connector/Node.js to version 3.2.5. Update MariaDB Connector/Node.js to version 3.3.4. Update MariaDB Connector/Node.js to version 3.4.7. Update MariaDB Connector/Node.js to version 3.5.4. As a temporary workaround, validate that GeoJSON coordinates are properly nested arrays of numbers before passing the object as a parameter. As a temporary workaround, use the query() function instead of execute() or batch().

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107383
GHSA-48QF-XH34-Q73R

Affected Products

Mariadb-Connector-Nodejs