{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mariadb-3.4.0--3.4.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55215"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mariadb (\u003c 3.2.4)","mariadb (3.3.0 – 3.3.2)","mariadb (3.4.0 – 3.4.5)","mariadb (3.5.0 – 3.5.2)"],"_cs_severities":["high"],"_cs_tags":["credential-theft","vulnerability","npm","nodejs"],"_cs_type":"advisory","_cs_vendors":["MariaDB"],"content_html":"\u003cp\u003eThe MariaDB connector for Node.js contains a high-severity vulnerability (CVE-2026-55215) where database credentials are transmitted in cleartext to an untrusted peer during the initial handshake. This occurs when SSL/TLS is enabled but the client is not configured to explicitly verify the server's certificate or CA. Under these conditions, the connector performs authentication before completing the identity validation check. While the connection eventually terminates due to a failed fingerprint validation, the damage occurs during the handshake when an active man-in-the-middle (MitM) attacker can capture the credentials by presenting any certificate to the client. This vulnerability affects multiple versions across the 3.x release branch. Organizations using the affected MariaDB npm package are at risk of credential exposure if network-level attackers can position themselves on the path between the application and the database server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the disclosure of database credentials, allowing an attacker to gain unauthorized access to the backend MariaDB instance. The impact is significant as it provides persistent access to sensitive data stored within the database. The scope includes any application environment using the vulnerable npm package where SSL/TLS is enabled without strict certificate validation (e.g., using default configurations or incomplete SSL settings).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the MariaDB npm package to the patched versions: 3.2.4, 3.3.3, 3.4.6, or 3.5.3.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, configure certificate verification explicitly in the connection settings.\u003c/li\u003e\n\u003cli\u003eEnsure the application provides the appropriate CA or server certificate and enforces \u003ccode\u003eVERIFY_CA\u003c/code\u003e or \u003ccode\u003eVERIFY_FULL\u003c/code\u003e modes to ensure identity validation occurs before authentication credentials are transmitted.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:14:50Z","date_published":"2026-08-28T21:14:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mariadb-mitm/","summary":"The MariaDB connector for Node.js (CVE-2026-55215) inadvertently sends database credentials during the handshake process before server identity is validated, enabling cleartext credential theft by an active man-in-the-middle.","title":"MariaDB Node.js Connector Credential Disclosure via MitM","url":"https://feed.craftedsignal.io/briefs/2026-08-mariadb-mitm/"}],"language":"en","title":"CraftedSignal Threat Feed - Mariadb (3.4.0 – 3.4.5)","version":"https://jsonfeed.org/version/1.1"}