To report security vulnerabilities, please follow our special security policy. Do not report security issues in the public issue tracker.
Security: MariaDB/server
Security
SECURITY.md
-
mysql_json plugin OOB readsGHSA-89ph-64cf-gqcc published
Sep 7, 2026 by vuvovaModerate -
`qc_info` plugin can do OOB reads if query contains \0GHSA-wfqg-88r5-55f6 published
Sep 7, 2026 by vuvovaModerate -
one byte OOB write in DOS tables of the CONNECT engineGHSA-4wgx-ffg9-jrwq published
Sep 7, 2026 by vuvovaHigh -
environment injection via wsrep bootstrap in the mariadb.service fileGHSA-mhvc-vqcq-7vq5 published
Sep 7, 2026 by vuvovaHigh -
libmariadb allowed cleartext password leakage on TLS hostname verification failureGHSA-fmq9-qjxj-qpf7 published
Sep 7, 2026 by vuvovaModerate -
insufficient validation of binary frm data when opening a tableGHSA-c4gx-34mg-95q5 published
Sep 7, 2026 by vuvovaHigh -
database privilege escalation via user / role name collision in the acl cacheGHSA-2m85-2x26-36rf published
Sep 7, 2026 by vuvovaModerate -
privilege escalation via incorrect view frm parsingGHSA-g2q2-3936-cp37 published
Sep 7, 2026 by vuvovaHigh -
Authorization bypass via ALTER TABLE ... CONVERT ... PARTITIONGHSA-h4vr-wpff-jfx4 published
Sep 7, 2026 by vuvovaHigh -
GRANT PROXY with empty password incorrectly checks grantor's privilegesGHSA-625w-4hgq-qwmr published
Sep 7, 2026 by vuvovaHigh
Learn more about advisories related to MariaDB/server in the GitHub Advisory Database