MariaDB Connector/Node.js 用于将基于 Node.js 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在 3.3.3、3.4.6 和 3.5.3 版本之前,当启用 SSL 且未固定 CA 或服务器证书时,MariaDB Connector/Node.js 会在完成证书指纹验证之前发送凭据。 具体漏洞细节如下: 在 中,如果服务器选择 作为初始身份验证插件,它可以在 TLS 连接后的身份检查完成之前接收到密码。 在 中,身份验证切换逻辑可能会错误地评估之前使用的插件,而非当前请
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | < 3.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | < 3.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55855 | 6.5 MEDIUM | MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/ |
| CVE-2026-55854 | 5.9 MEDIUM | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficien |
| CVE-2026-55856 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake |
| CVE-2026-55860 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clea |
| CVE-2026-55859 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding o |
| CVE-2026-55857 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Pr |
| CVE-2026-55858 | 5.9 MEDIUM | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb |
No comments yet