Medium · 4.9 Node.js & npm GHSA-48qf-xh34-q73r CVE-2026-107383
CVE-2026-107383 — MariaDB Connector/Node.js exposes uninitialized process memory via malformed GeoJSON
MariaDB Connector/Node.js can disclose uninitialized Node.js heap data when encoding malformed GeoJSON Polygon or MultiPolygon rings; fixed in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. [Sources: 4109, 31883]
AI summary
MariaDB Connector/Node.js contains a memory-disclosure flaw in its binary encoding of GeoJSON Polygon and MultiPolygon values. The issue can cause uninitialized heap bytes to be included in values sent to the database. Fixed vendor updates are available. [Sources: 4109, 31883]
What happened
The connector's GeoJSON Polygon and MultiPolygon binary encoders allocate a Buffer.allocUnsafe() sized from a ring's numeric length before confirming that the ring is actually an array. If a ring is malformed (not an array), the allocation reserves bytes that the subsequent write loop does not populate, and the connector can send the full buffer via execute() or batch(). That results in uninitialized Node.js heap data being persisted into a database value. The text-protocol query() path is not affected. [Sources: 4109, 31883]
Technical cause
Allocations are performed with Buffer.allocUnsafe() based on an unvalidated numeric length for each GeoJSON ring. The code sizes the buffer before verifying the ring is an array, so a malformed non-array ring can cause bytes to remain uninitialized while still included in the sent value. This is a classic information-disclosure issue (CWE-200). [Sources: 4109, 31883]
Why it matters
Persisted values may include uninitialized heap contents from the Node.js process. The vendor notes this can expose other users' content, session material, database credentials, or TLS key material; such data may also propagate to backups and replicas. Disclosure of those items can have high confidentiality impact. [Sources: 4109, 31883]
Who is affected
Applications using MariaDB Connector/Node.js (npm package 'mariadb') that send GeoJSON Polygon or MultiPolygon values through the binary encode path (execute() or batch()) are affected. The text-protocol query() path is not affected. [Sources: 4109, 31883]
Discovery and timeline
The issue was published in public vulnerability databases on 2026-10-08. There are no entries reporting public exploit code or that the flaw is known to be exploited in the wild. [Sources: 4109, 31883]
Affected and fixed versions
The vendor fixed the issue in the following releases: 3.2.5, 3.3.4, 3.4.7 and 3.5.4. Releases prior to each of those fixed releases in the corresponding series are affected. The 3.5 series includes an introduced event at 3.5.0-rc.0 and is fixed at 3.5.4. Check your installed mariadb npm package series and upgrade to the appropriate fixed release. [Sources: 4109, 31883]
Fixes and mitigation
Vendor updates are available that correct the encoder behavior. The fixes are included in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot immediately update, restrict or sanitize inputs that provide GeoJSON Polygon/MultiPolygon values and avoid using the binary encode path for untrusted data where feasible. [Sources: 4109, 31883]
Recommended action
Upgrade mariadb (the Connector/Node.js npm package) to one of the fixed releases (3.2.5, 3.3.4, 3.4.7 or 3.5.4) as soon as practical. Review any persisted GeoJSON data for signs of unexpected content and consider rotating exposed secrets and TLS keys if your deployment used affected connector versions and handled untrusted GeoJSON input. Confirm backups and replicas do not contain sensitive leaked data before restoring. Do not assume exploit code exists; however, treat exposed credentials or key material as compromised until rotated. [Sources: 4109, 31883]
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Why this score
CVSS v3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — network-exploitable, no privileges or user interaction required, with high confidentiality impact and no integrity or availability impact. PatchWire score 4.9 reflects the CVSS base plus factors for unauthenticated remote exposure and no user interaction required. [Sources: 4109, 31883]
Affected versions
- mariadb ≥ 3.5.0-rc.0 < 3.5.4
- vulnerable
- ≥ 3.2.5
- patched
- ≥ 3.3.4
- patched
- ≥ 3.4.7
- patched
- ≥ 3.5.4
- patched
Reported fixes
Vendor updates are available that correct the encoder behavior. The fixes are included in 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot immediately update, restrict or sanitize inputs that provide GeoJSON Polygon/MultiPolygon values and avoid using the binary encode path for untrusted data where feasible. [Sources: 4109, 31883]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email