Skip to main content

Threats Tagged 'cve-2026-107382'

View all threats tagged with 'cve-2026-107382'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-107382

Threats Tagged 'cve-2026-107382'

Click on any threat for detailed analysis and mitigation recommendations

### Description On the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server's identity from the fingerprint hash the server appends to the final OK_Packet (`Authentication.validateFingerPrint`). That validation calls `hash()` on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint. `Ed25519PasswordAuth.hash()` referenced an identifier `seed` that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static `encryptPassword(password, seed)`. Invoking the method therefore threw `ReferenceError: seed is not defined`. The throw happens synchronously inside the socket `data` handler, and no frame between `PacketInputStream.onData()` and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error. Because the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully — the failure is not limited to a hostile server. ### Impact Denial of service against the client process. Under Node's default `uncaughtException` behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only. An unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a `0x01`-prefixed validation hash. Exposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), `ssl: true` or an `ssl` object without `rejectUnauthorized: false`, a password set, no `ssl.ca` provided, and `client_ed25519` as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA. ### Resolution `Ed25519PasswordAuth.hash()` now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests. Fixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later. ### Workarounds Provide the server certificate to the client (`ssl: { ca: ... }`) so standard certificate validation is used instead of fingerprint validation, or set `ssl: { rejectUnauthorized: false }` to opt into trust mode, or use an authentication plugin other than `client_ed25519`, until upgraded. ### Credit Reported by fg0x0.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2026-107382
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses