PatchSiren cyber security CVE debrief
CVE-2026-107383 mariadb-corporation CVE debrief
CVE-2026-107383 is a high-severity vulnerability in MariaDB Connector/Node.js that exposes uninitialized process memory through malformed GeoJSON parameters. The vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4. A malformed non-array ring can reserve bytes that the writing loop skips, disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas.
- Vendor
- mariadb-corporation
- Product
- mariadb-connector-nodejs
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Node.js developers and administrators using MariaDB Connector/Node.js should assess exposure and prioritize upgrading to fixed versions. Database administrators and security teams should monitor for suspicious database queries or unusual data access patterns.
Why it matters
CVE-2026-107383 is a high-severity vulnerability in MariaDB Connector/Node.js that exposes uninitialized process memory through malformed GeoJSON parameters. Node.js developers and administrators should assess exposure and prioritize upgrading to fixed versions to prevent data exposure.
- Discloses uninitialized Node.js heap data into a database value
- May propagate sensitive data to backups and replicas
- Requires verification of affected versions and inventory
- Prioritize upgrading to fixed versions to prevent data exposure
Technical summary
The vulnerability is caused by the GeoJSON Polygon and MultiPolygon binary encoders sizing a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, disclosing uninitialized Node.js heap data into a database value. This issue allows attackers to access sensitive data, including other users' content, session material, database credentials, or TLS key material, which may propagate to backups and replicas. The vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Defensive priority
Defenders should prioritize upgrading to fixed versions 3.2.5, 3.3.4, 3.4.7, or 3.5.4. Assess exposure by checking if your Node.js applications use affected versions of MariaDB Connector/Node.js. Verify inventory and apply compensating controls, such as monitoring for suspicious database queries or unusual data access patterns.
Recommended defensive actions
- Upgrade to MariaDB Connector/Node.js version 3.2.5, 3.3.4, 3.4.7, or 3.5.4
- Assess exposure by checking if your Node.js applications use affected versions
- Verify inventory and apply compensating controls, such as monitoring for suspicious database queries or unusual data access patterns
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. The source item and supplemental sources, including GitHub advisories and commits, offer additional context and fix information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107383 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107383
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107383 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107383
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON paramet
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107383.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.