Denial of Service in MariaDB Server Due to Bound Check Flaw
CVE-2026-107815

8.5HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107815?

The MariaDB server, a community-developed fork of MySQL, is susceptible to a denial of service attack due to an incorrect boundary check in the CONNECT engine's DOS table type. This issue allows an authenticated user capable of utilizing the CONNECT engine to execute a one-byte null write beyond a stack buffer at an attacker-controlled offset. This flaw can lead to server crashes and potentially facilitate remote code execution. The problem affects several versions of MariaDB, and users are encouraged to update to fixed versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, or 13.0.2 to ensure protection against this vulnerability.

Affected Version(s)

server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28

server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19

server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.