MariaDB Connector/J 用于将 Java 应用连接到 MariaDB 和 MySQL 数据库。在 2.7.14、3.3.5、3.4.3 和 3.5.9 之前,该连接器在编码和解码协议文本以及执行客户端转义时,假设连接的字符集为 UTF-8。服务器可以通过 OK 数据包中的会话状态跟踪,报告会话期间 的变更,这些变更可能由 语句、存储过程或触发器、服务器配置或恶意服务器引起。如果 变为非 UTF-8 值,驱动程序将继续以 UTF-8 读写数据,而服务器则以另一种编码解释相同的字节流,从而导致静默的数据
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-j | < 2.7.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55215 | 7.5 HIGH | MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: |
| CVE-2026-55855 | 6.5 MEDIUM | MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/ |
| CVE-2026-55854 | 5.9 MEDIUM | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficien |
| CVE-2026-55856 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake |
| CVE-2026-55860 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clea |
| CVE-2026-55859 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding o |
| CVE-2026-55857 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Pr |
No comments yet