๐Ÿ” CVE Alert

CVE-2026-107817

MEDIUM 4.4

MariaDB: mysql_json plugin OOB reads

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contained valid MySQL binary JSON data. A specially prepared MySQL table containing invalid JSON data could cause out-of-bounds reads, information disclosure, or a server crash. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

CWE CWE-125
Vendor mariadb
Product server
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for mariadb server

Be the first to know when new medium vulnerabilities affecting mariadb server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

MariaDB / server
>= 10.6.1, < 10.6.28 >= 10.11.1, < 10.11.19 >= 11.4.1, < 11.4.13 >= 11.8.1, < 11.8.9 >= 12.3.1, < 12.3.3 >= 13.0.1, < 13.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MariaDB/server/security/advisories/GHSA-89ph-64cf-gqcc github.com: https://github.com/MariaDB/server/commit/851f52470d470a96a66e0b7e5599f3b6c2e45907 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-11.4.13 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-11.8.9 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-12.3.3 github.com: https://github.com/MariaDB/server/releases/tag/mariadb-13.0.2 jira.mariadb.org: https://jira.mariadb.org/browse/MDEV-40678