MariaDB 服务器是 MySQL 服务器的一个社区开发分支。在版本 10.6.1 至 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 和 13.0.2 中,mysql_json 插件假设导入的 MySQL 表包含有效的 MySQL 二进制 JSON 数据。精心构造的包含无效 JSON 数据的 MySQL 表可能导致越界读取、信息泄露或服务器崩溃。该问题已在版本 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 和 13.0.2 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
No comments yet