Skip to content
HackerOne Bug Bounty Disclosure: connector-c-out-of-bounds-read-in-unpack-fields-from-short-metadata-field-michal

HackerOne Bug Bounty Disclosure: connector-c-out-of-bounds-read-in-unpack-fields-from-short-metadata-field-michal

Redpacketsecurity •admin • September 30, 2026

Report title Connector/C Out-of-bounds read in `unpack_fields()` from short metadata field

Report link

Date submitted 2026-09-30T10:29:05.638Z

MariaDB Connector/C had a bug in unpack_fields(), which reads column metadata sent by a database server. The function assumed a metadata field contained at least 12 bytes, but did not check its length first. A malicious or compromised server could send a shorter field, causing the client to read beyond the field’s data.

Who could be affected

Applications using affected versions of MariaDB Connector/C could be at risk when connecting to a malicious or compromised database server. The report also notes that an attacker able to tamper with the connection could potentially trigger the issue.

The out-of-bounds read could crash the client application. Depending on the circumstances, it might also expose a limited amount of nearby process memory. The report does not establish that this memory disclosure can be reliably exploited.

MariaDB reports that the issue was fixed in Connector/C versions 3.3.20 and 3.4.10. Users should upgrade to a fixed version, especially if their applications connect to database servers they do not fully trust.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

HackerOne report summary

Programme

Submitted by Michal Schorm

Profile

Report title Connector/C Out-of-bounds read in `unpack_fields()` from short metadata field

Report link

Date submitted 2026-09-30T10:29:05.638Z

MariaDB Connector/C had a bug in unpack_fields(), which reads column metadata sent by a database server. The function assumed a metadata field contained at least 12 bytes, but did not check its length first. A malicious or compromised server could send a shorter field, causing the client to read beyond the field’s data.

Who could be affected

Applications using affected versions of MariaDB Connector/C could be at risk when connecting to a malicious or compromised database server. The report also notes that an attacker able to tamper with the connection could potentially trigger the issue.

The out-of-bounds read could crash the client application. Depending on the circumstances, it might also expose a limited amount of nearby process memory. The report does not establish that this memory disclosure can be reliably exploited.

MariaDB reports that the issue was fixed in Connector/C versions 3.3.20 and 3.4.10. Users should upgrade to a fixed version, especially if their applications connect to database servers they do not fully trust.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

CWE Weaknesses (1)