TLS Hostname Verification Vulnerability in MariaDB Connector/C Library
CVE-2026-107819
5.9MEDIUM
What is CVE-2026-107819?
The MariaDB Connector/C library prior to version 3.4.10 had a vulnerability in its SSL authentication-switch logic, which incorrectly handled certificate trust failures with regards to hostname verification. This flaw allowed an active man-in-the-middle attacker, possessing a valid SSL certificate for a different hostname, to exploit the situation. If they managed to request the mysql_clear_password, the attacker could compromise sensitive database credentials over a potentially insecure connection. This issue was addressed in version 3.4.10, underscoring the importance of careful hostname verification in securing database connections.
Affected Version(s)
server >= 3.4.1, < 3.4.10
