Vulnerability in MariaDB Server's MySQL JSON Plugin Enabling Out-of-Bounds Reads
CVE-2026-107817
4.4MEDIUM
What is CVE-2026-107817?
The MySQL JSON plugin in MariaDB Server, versions 10.6.1 through 10.6.28, as well as 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, incorrectly assumes imported MySQL tables contain valid MySQL binary JSON data. Attackers can exploit this flaw by providing specially crafted MySQL tables with invalid JSON data, potentially leading to out-of-bounds reads, information disclosure, or even causing the server to crash. Required fixes are included in subsequent updates, specifically versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
Affected Version(s)
server >= 10.6.1, < 10.6.28 < 10.6.1, 10.6.28
server >= 10.11.1, < 10.11.19 < 10.11.1, 10.11.19
server >= 11.4.1, < 11.4.13 < 11.4.1, 11.4.13
