{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107383", "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "state": "PUBLISHED", "assignerShortName": "GitHub_M", "dateReserved": "2026-10-07T21:07:54.988Z", "datePublished": "2026-10-08T18:27:02.543Z", "dateUpdated": "2026-10-08T18:27:02.543Z" }, "containers": { "cna": { "title": "MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-200", "lang": "en", "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" } } ], "references": [ { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r", "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7" }, { "name": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4" }, { "name": "https://jira.mariadb.org/browse/CONJS-367", "tags": [ "x_refsource_MISC" ], "url": "https://jira.mariadb.org/browse/CONJS-367" } ], "affected": [ { "vendor": "mariadb-corporation", "product": "mariadb-connector-nodejs", "versions": [ { "version": "< 3.2.5", "status": "affected" }, { "version": ">= 3.3.0, < 3.3.4", "status": "affected" }, { "version": ">= 3.4.0, < 3.4.7", "status": "affected" }, { "version": ">= 3.5.0-rc.0, < 3.5.4", "status": "affected" } ] } ], "providerMetadata": { "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M", "dateUpdated": "2026-10-08T18:27:02.543Z" }, "descriptions": [ { "lang": "en", "value": "MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4." } ], "source": { "advisory": "GHSA-48qf-xh34-q73r", "discovery": "UNKNOWN" } } } }