Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107385— MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES

Quick assessment

Affected
mariadb-corporation mariadb-connector-nodejs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MariaDB Connector/Node.js 用于将基于 Node.js 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在版本 3.2.5、3.3.4、3.4.7 和 3.5.4 之前,Text 协议转义始终在引号前添加反斜杠,且不尊重会话设置的 模式, 方法也存在此问题。当启用该模式时,反斜杠被视为普通字符,因此攻击者可以利用受控的占位符值闭合 SQL 字符串字面量,并以应用程序的数据库权限注入任意 SQL 语句。漏洞配置可能通过服务器全局设置、连接器初始化选项或应用发出的 命令启用;而 和

CVSS 7.4 · High

Affected Version Matrix 4

VendorProduct Version RangeStatus
mariadb-corporation mariadb-connector-nodejs < 3.2.5 affected
>= 3.3.0, < 3.3.4 affected
>= 3.4.0, < 3.4.7 affected
>= 3.5.0-rc.0, < 3.5.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107385

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
Source: CVE Program / CVE List V5
Vulnerability Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mariadb-corporation mariadb-connector-nodejs < 3.2.5 -

II. Public POCs for CVE-2026-107385

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107385

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107385 (4)

Other References for CVE-2026-107385 (6)

Same Patch Batch · mariadb-corporation · 2026-10-08 · 4 CVEs total

CVE-2026-107384 8.1 HIGH MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMu
CVE-2026-107383 7.5 HIGH MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON p
CVE-2026-107382 5.9 MEDIUM MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentica

IV. Related Vulnerabilities

V. Comments for CVE-2026-107385

No comments yet


Leave a comment