Back Redpacketsecurity HackerOne Bug Bounty Disclosure: connector-c-out-of-bounds-read-in-unpack-fields-from-short-metadata-field-michal
Report title Connector/C Out-of-bounds read in `unpack_fields()` from short metadata field
Report link
Date submitted 2026-09-30T10:29:05.638Z
MariaDB Connector/C had a bug in unpack_fields(), which reads column metadata sent by a database server. The function assumed a metadata field contained at least 12 bytes, but did not check its length first. A malicious or compromised server could send a shorter field, causing the client to read beyond the field’s data.
Who could be affected
Applications using affected versions of MariaDB Connector/C could be at risk when connecting to a malicious or compromised database server. The report also notes that an attacker able to tamper with the connection could potentially trigger the issue.
The out-of-bounds read could crash the client application. Depending on the circumstances, it might also expose a limited amount of nearby process memory. The report does not establish that this memory disclosure can be reliably exploited.
MariaDB reports that the issue was fixed in Connector/C versions 3.3.20 and 3.4.10. Users should upgrade to a fixed version, especially if their applications connect to database servers they do not fully trust.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
HackerOne report summary
Programme
Submitted by Michal Schorm
Profile
Report title Connector/C Out-of-bounds read in `unpack_fields()` from short metadata field
Report link
Date submitted 2026-09-30T10:29:05.638Z
MariaDB Connector/C had a bug in unpack_fields(), which reads column metadata sent by a database server. The function assumed a metadata field contained at least 12 bytes, but did not check its length first. A malicious or compromised server could send a shorter field, causing the client to read beyond the field’s data.
Who could be affected
Applications using affected versions of MariaDB Connector/C could be at risk when connecting to a malicious or compromised database server. The report also notes that an attacker able to tamper with the connection could potentially trigger the issue.
The out-of-bounds read could crash the client application. Depending on the circumstances, it might also expose a limited amount of nearby process memory. The report does not establish that this memory disclosure can be reliably exploited.
MariaDB reports that the issue was fixed in Connector/C versions 3.3.20 and 3.4.10. Users should upgrade to a fixed version, especially if their applications connect to database servers they do not fully trust.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
