CVE-2026-107817: MariaDB Server

Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contained valid MySQL binary JSON data. A specially prepared MySQL table containing invalid JSON data could cause out-of-bounds reads, information disclosure, or a server crash. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

Affected products

  • MariaDB Server: from 10.6.1, before 10.6.28 (fixed in 10.6.28); from 10.11.1, before 10.11.19 (fixed in 10.11.19); from 11.4.1, before 11.4.13 (fixed in 11.4.13); from 11.8.1, before 11.8.9 (fixed in 11.8.9); from 12.3.1, before 12.3.3 (fixed in 12.3.3); from 13.0.1, before 13.0.2 (fixed in 13.0.2)

Published 2026-10-09. Last modified 2026-10-09.