TLS Hostname Verification Vulnerability in MariaDB Connector/C Library
CVE-2026-107819

5.9MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107819?

The MariaDB Connector/C library prior to version 3.4.10 had a vulnerability in its SSL authentication-switch logic, which incorrectly handled certificate trust failures with regards to hostname verification. This flaw allowed an active man-in-the-middle attacker, possessing a valid SSL certificate for a different hostname, to exploit the situation. If they managed to request the mysql_clear_password, the attacker could compromise sensitive database credentials over a potentially insecure connection. This issue was addressed in version 3.4.10, underscoring the importance of careful hostname verification in securing database connections.

Affected Version(s)

server >= 3.4.1, < 3.4.10

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.