Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (client crash)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in MariaDB Connector/Node.js’s zero‑configuration TLS fingerprint‑validation path, which calls Ed25519PasswordAuth.hash() with a reference to an out‑of‑scope seed identifier. When a ReferenceError is thrown, it propagates out of the socket data handler; Node.js’s default uncaught‑exception behaviour terminates the client process, causing a denial of service. Affected products are MariaDB Corporation’s MariaDB Connector/Node.js versions from 3.3.0 up to but excluding 3.5.4; the issue was fixed in 3.5.4 and later. Only the connector library for MariaDB and MySQL is impacted. The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. An attacker must reach a MariaDB server over TCP with TLS enabled, a password set, the client_ed25519 authentication plugin negotiated, no CA configured, and rejectUnauthorized not set to false. A malicious server or network attacker presenting a self‑signed certificate can trigger the crash, leading to application termination but not compromising confidentiality or integrity.

Affected Systems

MariaDB Corporation’s MariaDB Connector/Node.js versions 3.3.0 through 3.5.3 (inclusive) are impacted; the library for MariaDB and MySQL. Versions 3.5.4 and later contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 5.9, indicating moderate severity; the EPSS score is not available, and it is not listed in CISA’s KEV catalog. Exploitation requires connecting to a MariaDB server over TCP with TLS enabled, a password set, the client_ed25519 authentication plugin negotiated, no CA configured, and rejectUnauthorized not set to false. An attacker presenting a self‑signed certificate can trigger a ReferenceError that propagates out of the socket data handler, causing the client process to crash and terminate. This results in denial of service but does not compromise data confidentiality or integrity.

Generated by OpenCVE AI on October 8, 2026 at 20:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to MariaDB Connector/Node.js 3.5.4 or later.
  • Configure the connector to use a valid TLS CA bundle (ssl.ca) or set rejectUnauthorized: false, thereby bypassing the vulnerable fingerprint validation path.
  • Avoid using the client_ed25519 authentication plugin; switch to another plugin that does not trigger the path.
  • If possible, use Unix sockets instead of TCP/TLS to eliminate the vulnerable code path.

Generated by OpenCVE AI on October 8, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cx2f-j9fh-8g68 MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
History

Thu, 08 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Mariadb
Mariadb connector-nodejs
Vendors & Products Mariadb
Mariadb connector-nodejs

Thu, 08 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.
Title MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mariadb Connector-nodejs
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:42:37.155Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107382

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:00.590

Modified: 2026-10-08T20:25:00.647

Link: CVE-2026-107382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:15:18Z

Weaknesses