Skip to content
MariaDB Connectors Vulnerable to Malicious Server Attacks

MariaDB Connectors Vulnerable to Malicious Server Attacks

First seen 30 Sep 2026, 19:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 20:30 UTC
  • •Connector/J and Connector/C have critical vulnerabilities that can be exploited by malicious servers.
  • •Users should upgrade to fixed versions immediately to prevent potential crashes and memory exposure.
  • •The vulnerabilities were disclosed on the same day, highlighting ongoing security concerns with MariaDB connectors.

Two vulnerabilities affecting MariaDB Connector/J and Connector/C were disclosed on September 30, 2026. Connector/J is susceptible to a denial-of-service attack where a malicious server can send an unbounded result-set field count, leading to a Java OutOfMemoryError and crashing the client JVM. Connector/C has an out-of-bounds read vulnerability in the unpack_fields() function, which could allow a malicious server to send shorter metadata fields, potentially crashing the client application and exposing nearby process memory. Both vulnerabilities were reported to HackerOne and have been patched in the respective versions: Connector/J in 2.7.15, 3.3.6, 3.4.4, and 3.5.10; Connector/C in 3.3.20 and 3.4.10. Users are advised to upgrade to these fixed versions to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
Connector/J vulnerability disclosed
A malicious server can crash the client JVM by sending an unbounded result-set field count, affecting applications using Connector/J.
Redpacketsecurity
2026-09-30
Connector/C vulnerability disclosed
An out-of-bounds read vulnerability in unpack_fields() could crash applications and expose memory when connecting to a malicious server.
Redpacketsecurity

More articles in this cluster (2)

Common questions

Which versions of MariaDB Connectors are affected?
Affected versions include Connector/J prior to 2.7.15, 3.3.6, 3.4.4, and 3.5.10, and Connector/C prior to 3.3.20 and 3.4.10.
What should users do to protect themselves?
Users should upgrade to the patched versions of Connector/J and Connector/C to mitigate the vulnerabilities.
Is there any evidence of active exploitation?
No evidence of active exploitation has been reported for these vulnerabilities as of now.