MariaDB Connector/Node.js 用于将基于 Node.js 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在版本 3.2.5、3.3.4、3.4.7 和 3.5.4 之前,Text 协议转义始终在引号前添加反斜杠,且不尊重会话设置的 模式, 方法也存在此问题。当启用该模式时,反斜杠被视为普通字符,因此攻击者可以利用受控的占位符值闭合 SQL 字符串字面量,并以应用程序的数据库权限注入任意 SQL 语句。漏洞配置可能通过服务器全局设置、连接器初始化选项或应用发出的 命令启用;而 和
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | < 3.2.5 |
affected |
>= 3.3.0, < 3.3.4 |
affected | ||
>= 3.4.0, < 3.4.7 |
affected | ||
>= 3.5.0-rc.0, < 3.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | < 3.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107384 | 8.1 HIGH | MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMu |
| CVE-2026-107383 | 7.5 HIGH | MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON p |
| CVE-2026-107382 | 5.9 MEDIUM | MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentica |
No comments yet