Redpacketsecurity MariaDB Connectors Vulnerable to Malicious Server Attacks
Article Content
- •Connector/J and Connector/C have critical vulnerabilities that can be exploited by malicious servers.
- •Users should upgrade to fixed versions immediately to prevent potential crashes and memory exposure.
- •The vulnerabilities were disclosed on the same day, highlighting ongoing security concerns with MariaDB connectors.
Two vulnerabilities affecting MariaDB Connector/J and Connector/C were disclosed on September 30, 2026. Connector/J is susceptible to a denial-of-service attack where a malicious server can send an unbounded result-set field count, leading to a Java OutOfMemoryError and crashing the client JVM. Connector/C has an out-of-bounds read vulnerability in the unpack_fields() function, which could allow a malicious server to send shorter metadata fields, potentially crashing the client application and exposing nearby process memory. Both vulnerabilities were reported to HackerOne and have been patched in the respective versions: Connector/J in 2.7.15, 3.3.6, 3.4.4, and 3.5.10; Connector/C in 3.3.20 and 3.4.10. Users are advised to upgrade to these fixed versions to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
Which versions of MariaDB Connectors are affected?
What should users do to protect themselves?
Is there any evidence of active exploitation?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…