Skip to main content

CVE-2026-107382: CWE-248: Uncaught Exception in mariadb-corporation mariadb-connector-nodejs

0
Medium
Published: 10/08/2026 (10/08/2026, 19:42:04 UTC)
Source: CVE Database V5
Vendor/Project: mariadb-corporation
Product: mariadb-connector-nodejs

Description

### Description On the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server's identity from the fingerprint hash the server appends to the final OK_Packet (`Authentication.validateFingerPrint`). That validation calls `hash()` on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint. `Ed25519PasswordAuth.hash()` referenced an identifier `seed` that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static `encryptPassword(password, seed)`. Invoking the method therefore threw `ReferenceError: seed is not defined`. The throw happens synchronously inside the socket `data` handler, and no frame between `PacketInputStream.onData()` and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error. Because the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully — the failure is not limited to a hostile server. ### Impact Denial of service against the client process. Under Node's default `uncaughtException` behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only. An unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a `0x01`-prefixed validation hash. Exposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), `ssl: true` or an `ssl` object without `rejectUnauthorized: false`, a password set, no `ssl.ca` provided, and `client_ed25519` as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA. ### Resolution `Ed25519PasswordAuth.hash()` now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests. Fixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later. ### Workarounds Provide the server certificate to the client (`ssl: { ca: ... }`) so standard certificate validation is used instead of fingerprint validation, or set `ssl: { rejectUnauthorized: false }` to opt into trust mode, or use an authentication plugin other than `client_ed25519`, until upgraded. ### Credit Reported by fg0x0.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

mariadb-corporation

mariadb-connector-nodejs

Affected versions
>=3.3.0 <3.5.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 20:37:51 UTC

Technical Analysis

In MariaDB Connector/Node.js versions >=3.3.0 and <3.5.4, the zero-configuration TLS fingerprint-validation path invokes Ed25519PasswordAuth.hash() via Authentication.validateFingerPrint. However, Ed25519PasswordAuth.hash() references a seed identifier that is out of scope, causing a synchronous ReferenceError exception to escape the socket data handler. This occurs only when connecting to a MariaDB server over TCP with TLS enabled (ssl: true or ssl object with rejectUnauthorized not false), a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under Node.js default uncaught-exception behavior, this exception terminates the client process, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, other authentication plugins, or Unix sockets do not trigger this issue. The vulnerability is resolved in version 3.5.4.

Potential Impact

The vulnerability causes a denial of service by terminating the Node.js client process when the uncaught ReferenceError exception occurs during TLS fingerprint validation. There is no impact on confidentiality or integrity. Exploitation requires specific TLS and authentication configurations and a reachable MariaDB server over TCP.

Mitigation Recommendations

Upgrade MariaDB Connector/Node.js to version 3.5.4 or later, where this issue is fixed. Alternatively, avoid configurations that trigger the vulnerable code path: use a configured CA certificate, set rejectUnauthorized to false, use a different authentication plugin than client_ed25519, or connect via Unix socket. These mitigations prevent the vulnerable code path from being reached.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.988Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7f4262cdf04f6563004d1

Added to database: 10/08/2026, 19:51:02 UTC

Last enriched: 10/08/2026, 20:37:51 UTC

Last updated: 10/08/2026, 21:45:50 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses