CVE-2026-55858Medium· 5.9▾ SunlitMariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a mid-session change to character_set_client through OK-packet session-state tracking, including a change caused by SET NAMES, a stored routine or trigger, server configuration, or a hostile server. If character_set_client changes to a non-UTF-8 value, the driver continues to read and write UTF-8 while the server interprets the same bytes under another encoding, causing silent data corruption and a client/server charset-confusion mismatch that can defeat byte-wise quoting or escaping. The fix accepts only utf8, utf8mb3, or utf8mb4 after initialization; any other value causes SQLException with SQLState 08000 and closes the connection. This issue is fixed in versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.mariadb.jdbc:mariadb-java-client < 2.7.14org.mariadb.jdbc:mariadb-java-client >= 3.0.0, < 3.3.5org.mariadb.jdbc:mariadb-java-client >= 3.4.0, < 3.4.3org.mariadb.jdbc:mariadb-java-client >= 3.5.0, < 3.5.9Patched in:
org.mariadb.jdbc:mariadb-java-client 2.7.14org.mariadb.jdbc:mariadb-java-client 3.3.5org.mariadb.jdbc:mariadb-java-client 3.4.3org.mariadb.jdbc:mariadb-java-client 3.5.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55856Medium· 5.9MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases
CVE-2026-55857Medium· 5.9MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases
CVE-2026-55859Medium· 5.9MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java
CVE-2026-55860Medium· 5.9MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java
CVE-2026-55855Medium· 6.5MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases
CVE-2026-55854Medium· 5.9MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases