<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mariadb (&lt; 3.2.5, &gt;= 3.3.0 &lt; 3.3.4, &gt;= 3.4.0 &lt; 3.4.7, &gt;= 3.5.0-Rc.0 &lt; 3.5.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mariadb--3.2.5--3.3.0--3.3.4--3.4.0--3.4.7--3.5.0-rc.0--3.5.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:43:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mariadb--3.2.5--3.3.0--3.3.4--3.4.0--3.4.7--3.5.0-rc.0--3.5.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>MariaDB Connector/Node.js Information Disclosure via Uninitialized Heap Memory</title><link>https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-memory-leak/</link><pubDate>Thu, 08 Oct 2026 19:43:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mariadb-node-memory-leak/</guid><description>An information disclosure vulnerability in the MariaDB Connector/Node.js allows attackers to leak uninitialized heap memory into database entries by providing malformed GeoJSON parameters to execute or batch operations.</description><content:encoded><![CDATA[<p>The MariaDB Connector/Node.js is vulnerable to an information disclosure issue (CVE-2026-107383) when encoding GeoJSON Polygon or MultiPolygon parameters. The connector incorrectly calculates the required buffer size for these objects using the 'length' property of provided rings. If an attacker provides a non-array object containing a 'length' property (e.g., {&quot;type&quot;: &quot;Polygon&quot;, &quot;coordinates&quot;: {&quot;length&quot;: 4000}}), the connector reserves space in a buffer allocated via Buffer.allocUnsafe() but fails to write the intended geometry data into that space.</p>
<p>Because the connector returns the entire buffer regardless of the write progress, the uninitialized heap memory remains in the returned buffer and is subsequently written to the database. This memory can contain sensitive data from the Node.js process, including other users' request/response bodies, session tokens, cookies, database credentials, and TLS key material. The issue affects all versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4. The text-based query() method is not affected.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the silent exfiltration of sensitive process heap data directly into the database. Because the leaked data is persisted in rows, backups, and replicas, it remains accessible to any entity with read permissions for the affected tables. This vulnerability poses a high risk to applications handling map or location data where attacker-supplied GeoJSON objects are processed by the connector.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to MariaDB Connector/Node.js version 3.2.5, 3.3.4, 3.4.7, 3.5.4, or later to implement proper validation of GeoJSON ring types.</li>
<li>Implement application-level input validation to ensure that all GeoJSON coordinate properties are correctly structured arrays before passing them to execute() or batch() methods.</li>
<li>Transition from execute() or batch() to the query() method for operations involving GeoJSON parameters if immediate patching is not feasible, as the text-based encoder is not impacted by this heap disclosure.</li>
<li>Audit database tables containing data populated by vulnerable versions of the connector to identify potentially leaked sensitive information.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>