Skip to main content

CVE-2026-107383: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in mariadb-corporation mariadb-connector-nodejs

0
High
Published: 10/08/2026 (10/08/2026, 19:42:11 UTC)
Source: CVE Database V5
Vendor/Project: mariadb-corporation
Product: mariadb-connector-nodejs

Description

### Description When encoding a GeoJSON Polygon or MultiPolygon parameter for the binary protocol, the connector sized its output buffer from the length property of each ring, then wrote each ring only if it was a real array. The two loops disagreed: any non-array ring carrying a numeric length (a string, or an object such as {"length": 4000}) still reserved 4 + 16 * length bytes, but wrote none of them. The buffer came from Buffer.allocUnsafe() and was returned in full regardless of how far the write position had advanced, so every reserved-but-unwritten byte was uninitialized Node.js heap. The sibling LineString case handled this correctly, aborting with null on the first malformed point, so no reserved byte could escape unwritten. The only gate on this path is value.type naming a GeoJSON type, so any object shaped like {"type": "Polygon", ...} reached the encoder. ### Impact An application that passes an attacker-influenced object as a parameter to execute() or batch() writes uninitialized process memory into the database, where it is readable by anyone who can read that row and persists into backups and replicas. Applications accepting GeoJSON for map or location features are the natural case, as the attacker controls coordinates directly. The disclosed memory is not scoped to the requesting user: in a shared Node.js process the heap may hold other users' request and response bodies, session tokens and cookies, database credentials and TLS key material. The leak is silent — the insert succeeds and the column simply holds more bytes than it should. No non-default connector option and no particular server configuration are required. query() is not affected: the text encoder builds geometry as strings rather than through Buffer.allocUnsafe(). ### Resolution Both the Polygon and MultiPolygon encoders now reject a non-array ring before reserving space for it, so no byte of the allocation can be left uninitialized by the writing loop, matching the existing LineString behaviour. ### Workarounds Validate that GeoJSON coordinates are properly nested arrays of numbers before passing the object as a parameter, or use query(), until upgraded.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

mariadb-corporation

mariadb-connector-nodejs

Affected versions
<3.2.5>=3.3.0 <3.3.4>=3.4.0 <3.4.7>=3.5.0-rc.0 <3.5.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 20:38:03 UTC

Technical Analysis

The vulnerability in MariaDB Connector/Node.js involves improper handling of GeoJSON Polygon and MultiPolygon binary encoders. Specifically, the connector uses Buffer.allocUnsafe() to allocate memory based on each ring's numeric length before confirming that the ring is an array. If a malformed non-array ring is processed, the connector reserves buffer bytes that are not overwritten, resulting in the transmission of uninitialized heap memory through execute() or batch() calls. This memory may contain sensitive data including other users' content, session material, database credentials, or TLS key material, which can also propagate to backups and replicas. The vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4 and is fixed in these versions. The text-protocol query() path is not affected.

Potential Impact

Exploitation of this vulnerability can lead to exposure of sensitive information such as other users' data, session information, database credentials, and TLS key material. This data leakage occurs through the binary encoding of GeoJSON Polygon and MultiPolygon data and can propagate to backups and replicas. The vulnerability does not impact data integrity or availability but poses a confidentiality risk.

Mitigation Recommendations

Upgrade MariaDB Connector/Node.js to version 3.2.5, 3.3.4, 3.4.7, or 3.5.4 or later, where this vulnerability is fixed. No other mitigation is indicated as the fix addresses the root cause.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.988Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7f4262cdf04f6563004d2

Added to database: 10/08/2026, 19:51:02 UTC

Last enriched: 10/08/2026, 20:38:03 UTC

Last updated: 10/08/2026, 21:45:50 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses