These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-55860 debrief based on CVE Program and NVD records. The CVE record was published on 2026-08-28T23:17:09.153Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects MariaDB Connector/R2DBC versions prior to 1.4.1, allowing clear-text password authentication plugins to be used over unencrypted connections. A hostile or man-in-the-middle MariaD [truncated]
This debrief provides an analysis of CVE-2026-55858, a vulnerability in MariaDB Connector/J that could lead to silent data corruption due to a character encoding mismatch between the client and server. The vulnerability arises when the connector assumes a UTF-8 connection character set but does not properly handle changes to this setting during a session, potentially causing data corruption or loss. Defen [truncated]
CVE-2026-55857 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T23:17:08.680Z and has not been modified since then. This vulnerability affects MariaDB Connector/J, which is used to connect applications developed in Java to MariaDB and MySQL databases. The issue involves improper configuration of the PAM dialog authentication, allowing account passwords to be transmit [truncated]
A vulnerability in MariaDB Connector/J allows an active man-in-the-middle or hostile server to present a self-signed certificate and receive the full database password before the connection is rejected. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9. The vulnerability arises when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not c [truncated]
CVE-2026-55855 MariaDB Connector/Node.js SQL Injection. The vulnerability allows attackers to inject SQL when using certain character sets. It affects versions prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Defenders should assess exposure and apply patches. The issue arises from improper escaping of Buffer parameters client-side, enabling SQL injection attacks. Successful exploitation can lead to data exposure [truncated]
CVE-2026-55854 MariaDB Connector/Node.js insecure transport vulnerability debrief. The vulnerability allows account password disclosure in MariaDB Connector/Node.js over insecure transport. Defenders responsible for Node.js applications using MariaDB Connector/Node.js, especially those with default sslMode=DISABLE and restrictedAuth=null settings, should assess exposure and prioritize verification and rem [truncated]
CVE-2026-55215 MariaDB Connector/Node.js Authentication Bypass. The vulnerability allows an active man-in-the-middle to capture database passwords and authenticate directly due to improper certificate validation and authentication plugin switching in MariaDB Connector/Node.js. Affected product deployments should be verified, and administrators should prioritize verification and remediation to prevent pote [truncated]