Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in MariaDB Connector/Node.js

MariaDB Connector/Node.js is vulnerable to multiple security flaws, including SQL injection, information disclosure, data manipulation, and denial-of-service, allowing remote unauthenticated attackers to compromise data.

CVE search metadata

CVE search record: CVE-2024-21088. Severity: high. CVSS: 7.5. EPSS: 0.52%. KEV: no. Product: Connector/Node.js. Brief: Multiple Vulnerabilities in MariaDB Connector/Node.js. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mariadb-connector-node/

CVE search record: CVE-2024-21096. Severity: medium. CVSS: 4.9. EPSS: 0.42%. KEV: no. Product: Connector/Node.js. Brief: Multiple Vulnerabilities in MariaDB Connector/Node.js. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mariadb-connector-node/

MariaDB Connector/Node.js contains multiple security vulnerabilities (CVE-2024-21088, CVE-2024-21096) that expose applications to significant risks. An unauthenticated remote attacker can exploit these flaws to perform SQL injection attacks, leading to the unauthorized disclosure or manipulation of database content. Furthermore, the vulnerabilities enable attackers to trigger a Denial of Service (DoS) condition, impacting the availability of the affected service. These issues affect the connector used for database communication in Node.js environments and represent a critical risk for backend systems relying on this library to interact with MariaDB databases. Defenders should identify all instances of the affected connector within their application stack and ensure updates are applied to remediate the underlying flaws.

Impact

Successful exploitation allows remote attackers to bypass security controls, resulting in complete database compromise including unauthorized data access, modification of records, or service disruption. This affects any application utilizing the vulnerable MariaDB Connector/Node.js library to handle database queries, potentially impacting confidentiality, integrity, and availability of backend data.

Recommendation

Prioritized actions for detection and remediation teams:

  • Inventory all Node.js applications to identify dependencies on MariaDB Connector/Node.js.
  • Review database query logs for patterns indicative of SQL injection attempts, such as unusual character sequences in query parameters.
  • Implement application-level input validation and parameterized queries to mitigate the risk of SQL injection until patches are deployed.
  • Upgrade MariaDB Connector/Node.js to the latest version as recommended by the vendor to remediate CVE-2024-21088 and CVE-2024-21096.

Immediate actions

Inventory all Node.js applications utilizing MariaDB Connector/Node.js

Application Security 48h

Mitigations

Upgrade MariaDB Connector/Node.js to patched version

immediate IT Operations

CVE-2024-21088, CVE-2024-21096