PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107383 mariadb-corporation CVE debrief

CVE-2026-107383 is a high-severity vulnerability in MariaDB Connector/Node.js that exposes uninitialized process memory through malformed GeoJSON parameters. The vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4. A malformed non-array ring can reserve bytes that the writing loop skips, disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas.

Vendor
mariadb-corporation
Product
mariadb-connector-nodejs
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Node.js developers and administrators using MariaDB Connector/Node.js should assess exposure and prioritize upgrading to fixed versions. Database administrators and security teams should monitor for suspicious database queries or unusual data access patterns.

Why it matters

CVE-2026-107383 is a high-severity vulnerability in MariaDB Connector/Node.js that exposes uninitialized process memory through malformed GeoJSON parameters. Node.js developers and administrators should assess exposure and prioritize upgrading to fixed versions to prevent data exposure.

  • Discloses uninitialized Node.js heap data into a database value
  • May propagate sensitive data to backups and replicas
  • Requires verification of affected versions and inventory
  • Prioritize upgrading to fixed versions to prevent data exposure

Technical summary

The vulnerability is caused by the GeoJSON Polygon and MultiPolygon binary encoders sizing a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, disclosing uninitialized Node.js heap data into a database value. This issue allows attackers to access sensitive data, including other users' content, session material, database credentials, or TLS key material, which may propagate to backups and replicas. The vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

Defensive priority

Defenders should prioritize upgrading to fixed versions 3.2.5, 3.3.4, 3.4.7, or 3.5.4. Assess exposure by checking if your Node.js applications use affected versions of MariaDB Connector/Node.js. Verify inventory and apply compensating controls, such as monitoring for suspicious database queries or unusual data access patterns.

Recommended defensive actions

  • Upgrade to MariaDB Connector/Node.js version 3.2.5, 3.3.4, 3.4.7, or 3.5.4
  • Assess exposure by checking if your Node.js applications use affected versions
  • Verify inventory and apply compensating controls, such as monitoring for suspicious database queries or unusual data access patterns
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. The source item and supplemental sources, including GitHub advisories and commits, offer additional context and fix information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107383 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107383

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107383 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107383

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON paramet

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107383.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.