Description
MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10. | |
| Title | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verification failure | |
| Weaknesses | CWE-297 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:59:15.334Z
Reserved: 2026-10-08T21:23:59.823Z
Link: CVE-2026-107819
No data.
Status : Received
Published: 2026-10-09T18:17:03.533
Modified: 2026-10-09T18:17:03.533
Link: CVE-2026-107819
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-297
Improper Validation of Certificate with Host Mismatch