PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107385 mariadb-corporation CVE debrief

A vulnerability in MariaDB Connector/Node.js allows for SQL injection when the session uses NO_BACKSLASH_ESCAPES. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges. Defenders should prioritize updating to fixed versions to prevent SQL injection attacks.

Vendor
mariadb-corporation
Product
mariadb-connector-nodejs
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders responsible for Node.js applications using MariaDB Connector/Node.js should assess exposure and prioritize updates to fixed versions. Defenders should review database connection settings to ensure NO_BACKSLASH_ESCAPES mode is properly handled and monitor database activity for suspicious SQL queries.

Why it matters

CVE-2026-107385 allows for SQL injection in MariaDB Connector/Node.js when NO_BACKSLASH_ESCAPES mode is enabled. Defenders should prioritize updates to fixed versions and review database connection settings.

  • SQL injection attacks may be possible with NO_BACKSLASH_ESCAPES mode enabled
  • Defenders must verify NO_BACKSLASH_ESCAPES mode usage in their applications
  • Remediation requires updating to fixed versions of MariaDB Connector/Node.js

Technical summary

The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected.

Defensive priority

Defenders should prioritize updating to fixed versions to prevent SQL injection attacks.

Recommended defensive actions

  • Update to version 3.2.5, 3.3.4, 3.4.7, or 3.5.4
  • Review and update database connection settings to ensure NO_BACKSLASH_ESCAPES mode is properly handled
  • Monitor database activity for suspicious SQL queries
  • Verify NO_BACKSLASH_ESCAPES mode usage in applications
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is caused by the text-protocol escaping always prefixing quotes with a backslash and not honoring the session's NO_BACKSLASH_ESCAPES mode. This issue can be exploited by an attacker-controlled placeholder value that closes the SQL string literal and injects arbitrary SQL with the application's database privileges.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107385 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107385

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107385 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107385

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107385.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-r3rv-jm3r-62q2

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6995c8cf8e51b2ad055de63dcaa4094eebbef5ce

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90949307e735c0ae148d80b3776478a599d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/95886df9fa0cca991e2be339caa6c3979be61553

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d732d9574177749488336319b73074072779

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3889197

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.