MariaDB Connector/Node.js 用于将基于 Node.js 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在版本 3.2.4、3.3.3、3.4.6 和 3.5.3 之前,当使用 big5、gbk、sjis、cp932 或 gb18030 客户端字符集时,MariaDB Connector/Node.js 允许通过客户端端转义攻击者可控的 Buffer 参数来触发 SQL 注入漏洞。 具体而言, 中的 在转义字节时,未应用 中基于字符集的多字节识别逻辑( )。由于服务器端的 SQ
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | < 3.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55215 | 7.5 HIGH | MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: |
| CVE-2026-55854 | 5.9 MEDIUM | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficien |
| CVE-2026-55856 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake |
| CVE-2026-55860 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clea |
| CVE-2026-55859 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding o |
| CVE-2026-55857 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Pr |
| CVE-2026-55858 | 5.9 MEDIUM | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb |
No comments yet