PT-2026-45150 · Mariadb Foundation+3 · Mariadb+3

CVE-2026-44172

·

Published

2026-05-26

·

Updated

2026-09-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MariaDB server versions 3.3.18 MariaDB server versions 3.4.8
Description An issue exists where applications using the big5 character set and text protocol are susceptible to SQL injections. This occurs when non-validated user input is processed by the mysql real escape string() function, which fails to properly prevent the injection in this specific configuration.
Recommendations Update MariaDB server version 3.3.18 to 3.3.19. Update MariaDB server version 3.4.8 to 3.4.9.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:43505
BIT-MARIADB-2026-44172
BIT-MARIADB-MIN-2026-44172
BIT-MYSQL-CLIENT-2026-44172
CVE-2026-44172
ECHO-6EA8-C8B9-7DDA
OESA-2026-3197
OPENSUSE-SU-2026:10897-1
OPENSUSE-SU-2026:11721-1
OPENSUSE-SU-2026:20933-1
OPENSUSE-SU-2026:21409-1
PYSEC-2026-217
RHSA-2026:30135
RHSA-2026:43505
RHSA-2026:47772
SUSE-SU-2026:22095-1
SUSE-SU-2026:22844-1
SUSE-SU-2026:2330-1
SUSE-SU-2026:3110-1
SUSE-SU-2026:3134-1
SUSE-SU-2026:3135-1
USN-8536-1

Affected Products

Mariadb
Red Os
Rocky Linux
Ubuntu