MariaDB Connector/Node.js 用于连接在 Node.js 上开发的应用程序与 MariaDB 和 MySQL 数据库。从版本 3.3.0 到 3.5.4,零配置 TLS 指纹验证路径通过 Authentication.validateFingerPrint 调用了 Ed25519PasswordAuth.hash(),但 Ed25519PasswordAuth.hash() 引用了一个作用域外的种子标识符(seed identifier)。 要利用此漏洞,需要满足以下条件: 1. 通过 TCP
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | >= 3.3.0, < 3.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | >= 3.3.0, < 3.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107384 | 8.1 HIGH | MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMu |
| CVE-2026-107383 | 7.5 HIGH | MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON p |
| CVE-2026-107385 | 7.4 HIGH | MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BAC |
No comments yet