CVE-2026-35549: MariaDB

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.

Affected products

  • MariaDB MariaDB: before 11.4.10 (fixed in 11.4.10); from 11.5.0, before 11.8.6 (fixed in 11.8.6); from 12.0.0, before 12.2.2 (fixed in 12.2.2)

Published 2026-04-03. Last modified 2026-07-24.