PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107382 mariadb-corporation CVE debrief

A vulnerability in MariaDB Connector/Node.js can cause an uncaught exception during ed25519 authentication with zero-configuration TLS, leading to a client crash. This issue arises from a reference error in the `Ed25519PasswordAuth.hash()` method. The vulnerability is triggered when the connector accepts a self-signed server certificate and attempts to validate the server's identity using a fingerprint hash.

Vendor
mariadb-corporation
Product
mariadb
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for MariaDB Connector/Node.js deployments, operators of affected systems, and security teams should assess their exposure to this vulnerability and prioritize updating to version 3.5.4 or later if necessary. This includes reviewing the current version of MariaDB Connector/Node.js in use, verifying potential exposure, and planning for updates or mitigations as needed. Vulnerability management and platform security teams should also be

Why it matters

A vulnerability in MariaDB Connector/Node.js can cause an uncaught exception during ed25519 authentication with zero-configuration TLS, leading to a client crash.

  • Verify affected versions of MariaDB Connector/Node.js in your environment.
  • Update to version 3.5.4 or later if necessary.
  • Monitor systems for unusual activity related to this vulnerability.

Technical summary

The vulnerability is caused by a reference error in the `Ed25519PasswordAuth.hash()` method, which is triggered during ed25519 authentication with zero-configuration TLS. The issue is resolved in version 3.5.4 of MariaDB Connector/Node.js. Affected product deployments should be verified and updated to this version or later to prevent client crashes due to uncaught exceptions. Defenders should prioritize verifying the affected versions of MariaDB Connector/Node.js in their environment and updating to version 3.5.4 or later if necessary.

Defensive priority

Defenders should prioritize verifying the affected versions of MariaDB Connector/Node.js in their environment and updating to version 3.5.4 or later if necessary.

Recommended defensive actions

  • Verify the version of MariaDB Connector/Node.js in your environment and update to version 3.5.4 or later if necessary.
  • Review your environment for potential exposure to this vulnerability.
  • Monitor your systems for any unusual activity related to this vulnerability.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The vulnerability is caused by a reference error in the `Ed25519PasswordAuth.hash()` method, which is triggered during ed25519 authentication with zero-configuration TLS. The issue is resolved in version 3.5.4 of MariaDB Connector/Node.js.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107382 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107382

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107382 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107382

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication w

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-cx2f-j9fh-8g68.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://jira.mariadb.org/browse/CONJS-356

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.