{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mariadb--3.2.5--3.3.0--3.3.4--3.4.0--3.4.7--3.5.0-rc.0--3.5.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107383"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mariadb (\u003c 3.2.5, \u003e= 3.3.0 \u003c 3.3.4, \u003e= 3.4.0 \u003c 3.4.7, \u003e= 3.5.0-rc.0 \u003c 3.5.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MariaDB"],"content_html":"\u003cp\u003eThe MariaDB Connector/Node.js is vulnerable to an information disclosure issue (CVE-2026-107383) when encoding GeoJSON Polygon or MultiPolygon parameters. The connector incorrectly calculates the required buffer size for these objects using the 'length' property of provided rings. If an attacker provides a non-array object containing a 'length' property (e.g., {\u0026quot;type\u0026quot;: \u0026quot;Polygon\u0026quot;, \u0026quot;coordinates\u0026quot;: {\u0026quot;length\u0026quot;: 4000}}), the connector reserves space in a buffer allocated via Buffer.allocUnsafe() but fails to write the intended geometry data into that space.\u003c/p\u003e\n\u003cp\u003eBecause the connector returns the entire buffer regardless of the write progress, the uninitialized heap memory remains in the returned buffer and is subsequently written to the database. This memory can contain sensitive data from the Node.js process, including other users' request/response bodies, session tokens, cookies, database credentials, and TLS key material. The issue affects all versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4. The text-based query() method is not affected.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the silent exfiltration of sensitive process heap data directly into the database. Because the leaked data is persisted in rows, backups, and replicas, it remains accessible to any entity with read permissions for the affected tables. This vulnerability poses a high risk to applications handling map or location data where attacker-supplied GeoJSON objects are processed by the connector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to MariaDB Connector/Node.js version 3.2.5, 3.3.4, 3.4.7, 3.5.4, or later to implement proper validation of GeoJSON ring types.\u003c/li\u003e\n\u003cli\u003eImplement application-level input validation to ensure that all GeoJSON coordinate properties are correctly structured arrays before passing them to execute() or batch() methods.\u003c/li\u003e\n\u003cli\u003eTransition from execute() or batch() to the query() method for operations involving GeoJSON parameters if immediate patching is not feasible, as the text-based encoder is not impacted by this heap disclosure.\u003c/li\u003e\n\u003cli\u003eAudit database tables containing data populated by vulnerable versions of the connector to identify potentially leaked sensitive information.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:43:44Z","date_published":"2026-10-08T19:43:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-memory-leak/","summary":"An information disclosure vulnerability in the MariaDB Connector/Node.js allows attackers to leak uninitialized heap memory into database entries by providing malformed GeoJSON parameters to execute or batch operations.","title":"MariaDB Connector/Node.js Information Disclosure via Uninitialized Heap Memory","url":"https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-memory-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Mariadb (\u003c 3.2.5, \u003e= 3.3.0 \u003c 3.3.4, \u003e= 3.4.0 \u003c 3.4.7, \u003e= 3.5.0-Rc.0 \u003c 3.5.4)","version":"https://jsonfeed.org/version/1.1"}