CVE-2026-107819: MariaDB Server
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.
Affected products
- MariaDB Server: from 3.4.1, before 3.4.10 (fixed in 3.4.10)
Published 2026-10-09. Last modified 2026-10-09.