Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-48qf-xh34-q73r CVE-2026-107383

CVE-2026-107383 — MariaDB Connector/Node.js exposes uninitialized process memory via malformed GeoJSON

MariaDB Connector/Node.js can disclose uninitialized Node.js heap data when encoding malformed GeoJSON Polygon or MultiPolygon rings; fixed in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. [Sources: 4109, 31883]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

MariaDB Connector/Node.js contains a memory-disclosure flaw in its binary encoding of GeoJSON Polygon and MultiPolygon values. The issue can cause uninitialized heap bytes to be included in values sent to the database. Fixed vendor updates are available. [Sources: 4109, 31883]

What happened

The connector's GeoJSON Polygon and MultiPolygon binary encoders allocate a Buffer.allocUnsafe() sized from a ring's numeric length before confirming that the ring is actually an array. If a ring is malformed (not an array), the allocation reserves bytes that the subsequent write loop does not populate, and the connector can send the full buffer via execute() or batch(). That results in uninitialized Node.js heap data being persisted into a database value. The text-protocol query() path is not affected. [Sources: 4109, 31883]

Technical cause

Allocations are performed with Buffer.allocUnsafe() based on an unvalidated numeric length for each GeoJSON ring. The code sizes the buffer before verifying the ring is an array, so a malformed non-array ring can cause bytes to remain uninitialized while still included in the sent value. This is a classic information-disclosure issue (CWE-200). [Sources: 4109, 31883]

Why it matters

Persisted values may include uninitialized heap contents from the Node.js process. The vendor notes this can expose other users' content, session material, database credentials, or TLS key material; such data may also propagate to backups and replicas. Disclosure of those items can have high confidentiality impact. [Sources: 4109, 31883]

Who is affected

Applications using MariaDB Connector/Node.js (npm package 'mariadb') that send GeoJSON Polygon or MultiPolygon values through the binary encode path (execute() or batch()) are affected. The text-protocol query() path is not affected. [Sources: 4109, 31883]

Discovery and timeline

The issue was published in public vulnerability databases on 2026-10-08. There are no entries reporting public exploit code or that the flaw is known to be exploited in the wild. [Sources: 4109, 31883]

Affected and fixed versions

The vendor fixed the issue in the following releases: 3.2.5, 3.3.4, 3.4.7 and 3.5.4. Releases prior to each of those fixed releases in the corresponding series are affected. The 3.5 series includes an introduced event at 3.5.0-rc.0 and is fixed at 3.5.4. Check your installed mariadb npm package series and upgrade to the appropriate fixed release. [Sources: 4109, 31883]

Fixes and mitigation

Vendor updates are available that correct the encoder behavior. The fixes are included in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot immediately update, restrict or sanitize inputs that provide GeoJSON Polygon/MultiPolygon values and avoid using the binary encode path for untrusted data where feasible. [Sources: 4109, 31883]

Recommended action

Upgrade mariadb (the Connector/Node.js npm package) to one of the fixed releases (3.2.5, 3.3.4, 3.4.7 or 3.5.4) as soon as practical. Review any persisted GeoJSON data for signs of unexpected content and consider rotating exposed secrets and TLS keys if your deployment used affected connector versions and handled untrusted GeoJSON input. Confirm backups and replicas do not contain sensitive leaked data before restoring. Do not assume exploit code exists; however, treat exposed credentials or key material as compromised until rotated. [Sources: 4109, 31883]

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Why this score

CVSS v3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — network-exploitable, no privileges or user interaction required, with high confidentiality impact and no integrity or availability impact. PatchWire score 4.9 reflects the CVSS base plus factors for unauthenticated remote exposure and no user interaction required. [Sources: 4109, 31883]

Affected versions

mariadb ≥ 3.5.0-rc.0 < 3.5.4
vulnerable
≥ 3.2.5
patched
≥ 3.3.4
patched
≥ 3.4.7
patched
≥ 3.5.4
patched

Reported fixes

Vendor updates are available that correct the encoder behavior. The fixes are included in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot immediately update, restrict or sanitize inputs that provide GeoJSON Polygon/MultiPolygon values and avoid using the binary encode path for untrusted data where feasible. [Sources: 4109, 31883]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
CVE-2026-107383 — MariaDB Connector/Node.js exposes uninitialized process memory via malformed GeoJSON
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email