Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Information Disclosure of Sensitive Database Data
Action: Immediate Patch
AI Analysis

Impact

MariaDB Connector/Node.js contains a flaw in the GeoJSON Polygon and MultiPolygon binary encoders that allocates a buffer of unsafe size based on each ring’s numeric length before it verifies that the ring is an actual array. A bad request with a non‑array ring therefore reserves bytes that the encoder never writes, causing the fill loop to skip them. The connector then transmits the entire uninitialized buffer to the database through execute() or batch(), exposing raw Node.js heap contents. Depending on the process state, the leaked data may include other users’ information, session tokens, database credentials, or TLS private keys, which can persist in database values, backups, or replicas.

Affected Systems

The vulnerability affects MariaDB Connector/Node.js versions prior to 3.2.5, 3.3.4, 3.4.7 and 3.5.4. Any application using these releases to connect Node.js services to MariaDB or MySQL should be considered at risk.

Risk and Exploitability

The CVSS score of 7.5 reflects a high risk of confidential data exposure. Although no EPSS score is available, the lack of a KEV listing suggests the exploit is not actively used in the wild yet, but it remains operable if an attacker can supply malformed GeoJSON to the connector. The attack vector is inferred to be directed at applications that process or store user-supplied GeoJSON, requiring control over the input data but not privileged system access or remote code execution capability.

Generated by OpenCVE AI on October 8, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MariaDB Connector/Node.js to version 3.2.5 or later; the vendor releases 3.3.4, 3.4.7 and 3.5.4 contain the fix.
  • Validate GeoJSON input so that every ring inside a Polygon or MultiPolygon is confirmed to be an array before passing it to the connector, preventing unsafe buffer allocation.
  • Restrict use of the affected GeoJSON functions in the application until the connector is upgraded, or remove them from production code to limit exposure.

Generated by OpenCVE AI on October 8, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-48qf-xh34-q73r MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mariadb
Mariadb connector-nodejs
Vendors & Products Mariadb
Mariadb connector-nodejs

Thu, 08 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Title MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mariadb Connector-nodejs
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:27:02.543Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:00.783

Modified: 2026-10-08T20:25:00.647

Link: CVE-2026-107383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor