PatchSiren cyber security CVE debrief
CVE-2026-107385 mariadb-corporation CVE debrief
A vulnerability in MariaDB Connector/Node.js allows for SQL injection when the session uses NO_BACKSLASH_ESCAPES. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges. Defenders should prioritize updating to fixed versions to prevent SQL injection attacks.
- Vendor
- mariadb-corporation
- Product
- mariadb-connector-nodejs
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Node.js applications using MariaDB Connector/Node.js should assess exposure and prioritize updates to fixed versions. Defenders should review database connection settings to ensure NO_BACKSLASH_ESCAPES mode is properly handled and monitor database activity for suspicious SQL queries.
Why it matters
CVE-2026-107385 allows for SQL injection in MariaDB Connector/Node.js when NO_BACKSLASH_ESCAPES mode is enabled. Defenders should prioritize updates to fixed versions and review database connection settings.
- SQL injection attacks may be possible with NO_BACKSLASH_ESCAPES mode enabled
- Defenders must verify NO_BACKSLASH_ESCAPES mode usage in their applications
- Remediation requires updating to fixed versions of MariaDB Connector/Node.js
Technical summary
The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected.
Defensive priority
Defenders should prioritize updating to fixed versions to prevent SQL injection attacks.
Recommended defensive actions
- Update to version 3.2.5, 3.3.4, 3.4.7, or 3.5.4
- Review and update database connection settings to ensure NO_BACKSLASH_ESCAPES mode is properly handled
- Monitor database activity for suspicious SQL queries
- Verify NO_BACKSLASH_ESCAPES mode usage in applications
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107385 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107385
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107385 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107385
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107385.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-r3rv-jm3r-62q2
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6995c8cf8e51b2ad055de63dcaa4094eebbef5ce
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90949307e735c0ae148d80b3776478a599d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/95886df9fa0cca991e2be339caa6c3979be61553
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d732d9574177749488336319b73074072779
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://hackerone.com/reports/3889197
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.