CVE-2026-107383 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.
Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
Affected
- Vendor
- npm
- Product
- mariadb
Versions
- pkg:npm/mariadb < 3.2.5
- pkg:npm/mariadb >= 3.3.0, < 3.3.4
- pkg:npm/mariadb >= 3.4.0, < 3.4.7
- pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4
- otherOSV webhttps://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r
- otherOSV webhttps://jira.mariadb.org/browse/CONJS-367
- advisoryOSV GHSA-48qf-xh34-q73rhttps://osv.dev/vulnerability/GHSA-48qf-xh34-q73r
- vendorOSV packagehttps://github.com/mariadb-corporation/mariadb-connector-nodejs
Related threats
same CWE or vendorCVE-2026-84274 — IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability.
CVE-2026-84274 · 2h ago
CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107392 · 2h ago
CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107391 · 2h ago
CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107389 · 2h ago
CVE-2026-107388 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107388 · 3h ago
CVE-2026-107387 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107387 · 3h ago