Denial of Service Vulnerability in MariaDB Connector for Node.js
CVE-2026-107382
5.9MEDIUM
What is CVE-2026-107382?
The MariaDB Connector/Node.js versions 3.3.0 through 3.5.4 have a vulnerability linked to the Ed25519 password authentication which can lead to a denial of service. In unsafe configurations where a MariaDB server is accessed via TCP with TLS enabled, a malicious server or network attacker may exploit this vulnerability. Specifically, an uncaught synchronous ReferenceError can occur due to a scope issue with a seed identifier, causing the client process to terminate under Node.js's default error handling behavior. Users are encouraged to upgrade to version 3.5.4 or later, where this vulnerability is addressed to ensure better security efficacy.
Affected Version(s)
mariadb-connector-nodejs >= 3.3.0, < 3.5.4
