Impact
MariaDB Connector/Node.js contains a flaw in the GeoJSON Polygon and MultiPolygon binary encoders that allocates a buffer of unsafe size based on each ring’s numeric length before it verifies that the ring is an actual array. A bad request with a non‑array ring therefore reserves bytes that the encoder never writes, causing the fill loop to skip them. The connector then transmits the entire uninitialized buffer to the database through execute() or batch(), exposing raw Node.js heap contents. Depending on the process state, the leaked data may include other users’ information, session tokens, database credentials, or TLS private keys, which can persist in database values, backups, or replicas.
Affected Systems
The vulnerability affects MariaDB Connector/Node.js versions prior to 3.2.5, 3.3.4, 3.4.7 and 3.5.4. Any application using these releases to connect Node.js services to MariaDB or MySQL should be considered at risk.
Risk and Exploitability
The CVSS score of 7.5 reflects a high risk of confidential data exposure. Although no EPSS score is available, the lack of a KEV listing suggests the exploit is not actively used in the wild yet, but it remains operable if an attacker can supply malformed GeoJSON to the connector. The attack vector is inferred to be directed at applications that process or store user-supplied GeoJSON, requiring control over the input data but not privileged system access or remote code execution capability.
OpenCVE Enrichment
Github GHSA