PatchSiren cyber security CVE debrief
CVE-2026-107382 mariadb-corporation CVE debrief
A vulnerability in MariaDB Connector/Node.js can cause an uncaught exception during ed25519 authentication with zero-configuration TLS, leading to a client crash. This issue arises from a reference error in the `Ed25519PasswordAuth.hash()` method. The vulnerability is triggered when the connector accepts a self-signed server certificate and attempts to validate the server's identity using a fingerprint hash.
- Vendor
- mariadb-corporation
- Product
- mariadb
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for MariaDB Connector/Node.js deployments, operators of affected systems, and security teams should assess their exposure to this vulnerability and prioritize updating to version 3.5.4 or later if necessary. This includes reviewing the current version of MariaDB Connector/Node.js in use, verifying potential exposure, and planning for updates or mitigations as needed. Vulnerability management and platform security teams should also be
Why it matters
A vulnerability in MariaDB Connector/Node.js can cause an uncaught exception during ed25519 authentication with zero-configuration TLS, leading to a client crash.
- Verify affected versions of MariaDB Connector/Node.js in your environment.
- Update to version 3.5.4 or later if necessary.
- Monitor systems for unusual activity related to this vulnerability.
Technical summary
The vulnerability is caused by a reference error in the `Ed25519PasswordAuth.hash()` method, which is triggered during ed25519 authentication with zero-configuration TLS. The issue is resolved in version 3.5.4 of MariaDB Connector/Node.js. Affected product deployments should be verified and updated to this version or later to prevent client crashes due to uncaught exceptions. Defenders should prioritize verifying the affected versions of MariaDB Connector/Node.js in their environment and updating to version 3.5.4 or later if necessary.
Defensive priority
Defenders should prioritize verifying the affected versions of MariaDB Connector/Node.js in their environment and updating to version 3.5.4 or later if necessary.
Recommended defensive actions
- Verify the version of MariaDB Connector/Node.js in your environment and update to version 3.5.4 or later if necessary.
- Review your environment for potential exposure to this vulnerability.
- Monitor your systems for any unusual activity related to this vulnerability.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The vulnerability is caused by a reference error in the `Ed25519PasswordAuth.hash()` method, which is triggered during ed25519 authentication with zero-configuration TLS. The issue is resolved in version 3.5.4 of MariaDB Connector/Node.js.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107382 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107382
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107382 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107382
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication w
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-cx2f-j9fh-8g68.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://jira.mariadb.org/browse/CONJS-356
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.