Denial of Service Vulnerability in MariaDB Connector for Node.js
CVE-2026-107382

5.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107382?

The MariaDB Connector/Node.js versions 3.3.0 through 3.5.4 have a vulnerability linked to the Ed25519 password authentication which can lead to a denial of service. In unsafe configurations where a MariaDB server is accessed via TCP with TLS enabled, a malicious server or network attacker may exploit this vulnerability. Specifically, an uncaught synchronous ReferenceError can occur due to a scope issue with a seed identifier, causing the client process to terminate under Node.js's default error handling behavior. Users are encouraged to upgrade to version 3.5.4 or later, where this vulnerability is addressed to ensure better security efficacy.

Affected Version(s)

mariadb-connector-nodejs >= 3.3.0, < 3.5.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.