Impact
The vulnerability lies in MariaDB Connector/Node.js’s zero‑configuration TLS fingerprint‑validation path, which calls Ed25519PasswordAuth.hash() with a reference to an out‑of‑scope seed identifier. When a ReferenceError is thrown, it propagates out of the socket data handler; Node.js’s default uncaught‑exception behaviour terminates the client process, causing a denial of service. Affected products are MariaDB Corporation’s MariaDB Connector/Node.js versions from 3.3.0 up to but excluding 3.5.4; the issue was fixed in 3.5.4 and later. Only the connector library for MariaDB and MySQL is impacted. The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. An attacker must reach a MariaDB server over TCP with TLS enabled, a password set, the client_ed25519 authentication plugin negotiated, no CA configured, and rejectUnauthorized not set to false. A malicious server or network attacker presenting a self‑signed certificate can trigger the crash, leading to application termination but not compromising confidentiality or integrity.
Affected Systems
MariaDB Corporation’s MariaDB Connector/Node.js versions 3.3.0 through 3.5.3 (inclusive) are impacted; the library for MariaDB and MySQL. Versions 3.5.4 and later contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity; the EPSS score is not available, and it is not listed in CISA’s KEV catalog. Exploitation requires connecting to a MariaDB server over TCP with TLS enabled, a password set, the client_ed25519 authentication plugin negotiated, no CA configured, and rejectUnauthorized not set to false. An attacker presenting a self‑signed certificate can trigger a ReferenceError that propagates out of the socket data handler, causing the client process to crash and terminate. This results in denial of service but does not compromise data confidentiality or integrity.
OpenCVE Enrichment
Github GHSA