Common Weakness Enumeration

CWE-248

Allowed

Uncaught Exception

Abstraction: Base · Status: Draft

An exception is thrown from a function, but it is not caught.

610 vulnerabilities reference this CWE, most recent first.

GHSA-CCG5-9C8W-XH6V

Vulnerability from github – Published: 2026-09-09 18:01 – Updated: 2026-09-09 18:01
VLAI
Summary
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Details

Summary

ModelView.sort_query() uses the attacker-controlled sortBy list-view query parameter without checking it against the configured column_sortable_list allow-list. The value is resolved with getattr(model, ...) and fed into relationship joins and order_by(), so a request can sort by any column of the model — including ones hidden from column_list — and, via a dotted path, by columns of related models. Because row order then reflects the value of an unexposed column, this is an information-exposure ordering oracle.

Root cause

column_sortable_list is consulted only in the list template to decide which header links to render; the server never enforces it, so removing a column from the UI does not prevent sorting by it.

Exploitation

A single request leaks the relative ordering of an unexposed column; the asc↔desc reversal confirms rows are ordered by the secret's actual value. Pairing sortBy with searchable/filterable columns and pagination can narrow the oracle toward specific values, though value recovery is conditional on having a filterable target column.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "sqladmin"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.27.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-54529"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-20",
      "CWE-200",
      "CWE-248",
      "CWE-639"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-09T18:01:56Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "## Summary\n\n`ModelView.sort_query()` uses the attacker-controlled `sortBy` list-view query parameter without checking it against the configured `column_sortable_list` allow-list. The value is resolved with `getattr(model, ...)` and fed into relationship joins and `order_by()`, so a request can sort by **any** column of the model \u2014 including ones hidden from `column_list` \u2014 and, via a dotted path, by columns of related models. Because row order then reflects the value of an unexposed column, this is an information-exposure **ordering oracle**.\n\n## Root cause\n\n`column_sortable_list` is consulted only in the list template to decide which header links to render; the server never enforces it, so removing a column from the UI does not prevent sorting by it.\n\n## Exploitation\n\nA single request leaks the relative ordering of an unexposed column; the `asc`\u2194`desc` reversal confirms rows are ordered by the secret\u0027s actual value. Pairing `sortBy` with searchable/filterable columns and pagination can narrow the oracle toward specific values, though value recovery is conditional on having a filterable target column.",
  "id": "GHSA-ccg5-9c8w-xh6v",
  "modified": "2026-09-09T18:01:56Z",
  "published": "2026-09-09T18:01:56Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/smithyhq/sqladmin/security/advisories/GHSA-ccg5-9c8w-xh6v"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/smithyhq/sqladmin"
    },
    {
      "type": "WEB",
      "url": "https://github.com/smithyhq/sqladmin/releases/tag/0.27.1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`"
}

GHSA-CF9C-6VVV-M2RC

Vulnerability from github – Published: 2025-04-07 06:30 – Updated: 2025-04-07 06:30
VLAI
Details

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-58112"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-04-07T04:15:17Z",
    "severity": "HIGH"
  },
  "details": "Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework\nImpact: Successful exploitation of this vulnerability may affect availability.",
  "id": "GHSA-cf9c-6vvv-m2rc",
  "modified": "2025-04-07T06:30:27Z",
  "published": "2025-04-07T06:30:27Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58112"
    },
    {
      "type": "WEB",
      "url": "https://consumer.huawei.com/en/support/bulletin/2025/4"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-CHH6-2PFH-PC8W

Vulnerability from github – Published: 2026-09-28 18:31 – Updated: 2026-09-28 18:31
VLAI
Details

A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-101101"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-28T18:17:17Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.",
  "id": "GHSA-chh6-2pfh-pc8w",
  "modified": "2026-09-28T18:31:26Z",
  "published": "2026-09-28T18:31:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101101"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2444"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2493"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ag-ui-protocol/ag-ui/commit/30f8c794d5b73df5c610153043db502b2cc106cc"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ag-ui-protocol/ag-ui"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/release/2026-09-08"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/cve/CVE-2026-101101"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/submit/934981"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/410976"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/410976/cti"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-CM8H-Q92V-XCFC

Vulnerability from github – Published: 2023-01-09 21:55 – Updated: 2023-01-10 16:15
VLAI
Summary
mercurius has Uncaught Exception when using subscriptions
Details

Impact

Any users of Mercurius until version v11.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to /graphql.

Patches

This was patched in https://github.com/mercurius-js/mercurius/pull/940. The patch was released as v11.5.0 and v8.13.2.

Workarounds

Disable subscriptions.

References

Reported publicly as https://github.com/mercurius-js/mercurius/issues/939. The same problem was solved in https://github.com/fastify/fastify-websocket/pull/228

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "mercurius"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0"
            },
            {
              "fixed": "11.5.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "mercurius"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.13.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2023-22477"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-01-09T21:55:44Z",
    "nvd_published_at": "2023-01-09T15:15:00Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\n\nAny users of Mercurius until version v11.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`.\n\n### Patches\n\nThis was patched in https://github.com/mercurius-js/mercurius/pull/940.\nThe patch was released as v11.5.0 and v8.13.2.\n\n### Workarounds\n\nDisable subscriptions.\n\n### References\n\nReported publicly as https://github.com/mercurius-js/mercurius/issues/939.\nThe same problem was solved in https://github.com/fastify/fastify-websocket/pull/228\n",
  "id": "GHSA-cm8h-q92v-xcfc",
  "modified": "2023-01-10T16:15:07Z",
  "published": "2023-01-09T21:55:44Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/mercurius-js/mercurius/security/advisories/GHSA-cm8h-q92v-xcfc"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22477"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mercurius-js/mercurius/issues/939"
    },
    {
      "type": "WEB",
      "url": "https://github.com/fastify/fastify-websocket/pull/228"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mercurius-js/mercurius/pull/940"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/mercurius-js/mercurius"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "mercurius has Uncaught Exception when using subscriptions"
}

GHSA-CP7V-2P64-673R

Vulnerability from github – Published: 2024-04-27 00:30 – Updated: 2024-09-27 18:32
VLAI
Details

Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time. 

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-3051"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248",
      "CWE-345"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-04-26T22:15:08Z",
    "severity": "HIGH"
  },
  "details": "Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time.\u00a0",
  "id": "GHSA-cp7v-2p64-673r",
  "modified": "2024-09-27T18:32:21Z",
  "published": "2024-04-27T00:30:37Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3051"
    },
    {
      "type": "WEB",
      "url": "https://community.silabs.com/068Vm0000045w2j"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-CP97-6MF7-2CVP

Vulnerability from github – Published: 2023-11-14 21:31 – Updated: 2023-11-14 21:31
VLAI
Details

Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-22292"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248",
      "CWE-755"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-11-14T19:15:16Z",
    "severity": "HIGH"
  },
  "details": "Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.",
  "id": "GHSA-cp97-6mf7-2cvp",
  "modified": "2023-11-14T21:31:01Z",
  "published": "2023-11-14T21:31:01Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22292"
    },
    {
      "type": "WEB",
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-CQMH-QFGQ-FXF4

Vulnerability from github – Published: 2026-07-18 15:31 – Updated: 2026-07-18 15:31
VLAI
Details

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-58364"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-18T14:17:09Z",
    "severity": "HIGH"
  },
  "details": "SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic in the span rendering code, crashing the server and causing denial of service.",
  "id": "GHSA-cqmh-qfgq-fxf4",
  "modified": "2026-07-18T15:31:48Z",
  "published": "2026-07-18T15:31:48Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-8xff-473h-f863"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58364"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-parsing-error"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-CW9R-3WQP-32HM

Vulnerability from github – Published: 2026-09-30 21:32 – Updated: 2026-09-30 21:32
VLAI
Details

A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-103387"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-30T20:17:30Z",
    "severity": "LOW"
  },
  "details": "A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
  "id": "GHSA-cw9r-3wqp-32hm",
  "modified": "2026-09-30T21:32:10Z",
  "published": "2026-09-30T21:32:09Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-103387"
    },
    {
      "type": "WEB",
      "url": "https://github.com/garycourt/uri-js/issues/103"
    },
    {
      "type": "WEB",
      "url": "https://github.com/garycourt/uri-js"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/cve/CVE-2026-103387"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/submit/956810"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/412124"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/412124/cti"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-CX2F-J9FH-8G68

Vulnerability from github – Published: 2026-10-08 19:42 – Updated: 2026-10-08 19:42
VLAI
Summary
MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
Details

Description

On the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server's identity from the fingerprint hash the server appends to the final OK_Packet (Authentication.validateFingerPrint). That validation calls hash() on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint.

Ed25519PasswordAuth.hash() referenced an identifier seed that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static encryptPassword(password, seed). Invoking the method therefore threw ReferenceError: seed is not defined.

The throw happens synchronously inside the socket data handler, and no frame between PacketInputStream.onData() and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error.

Because the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully — the failure is not limited to a hostile server.

Impact

Denial of service against the client process. Under Node's default uncaughtException behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only.

An unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a 0x01-prefixed validation hash.

Exposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), ssl: true or an ssl object without rejectUnauthorized: false, a password set, no ssl.ca provided, and client_ed25519 as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA.

Resolution

Ed25519PasswordAuth.hash() now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests.

Fixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later.

Workarounds

Provide the server certificate to the client (ssl: { ca: ... }) so standard certificate validation is used instead of fingerprint validation, or set ssl: { rejectUnauthorized: false } to opt into trust mode, or use an authentication plugin other than client_ed25519, until upgraded.

Credit

Reported by fg0x0.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "mariadb"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.3.0"
            },
            {
              "fixed": "3.5.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-107382"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T19:42:04Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Description\nOn the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server\u0027s identity from the fingerprint hash the server appends to the final OK_Packet (`Authentication.validateFingerPrint`). That validation calls `hash()` on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint.\n\n`Ed25519PasswordAuth.hash()` referenced an identifier `seed` that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static `encryptPassword(password, seed)`. Invoking the method therefore threw `ReferenceError: seed is not defined`.\n\nThe throw happens synchronously inside the socket `data` handler, and no frame between `PacketInputStream.onData()` and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error.\n\nBecause the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully \u2014 the failure is not limited to a hostile server.\n\n### Impact\nDenial of service against the client process. Under Node\u0027s default `uncaughtException` behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only.\n\nAn unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a `0x01`-prefixed validation hash.\n\nExposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), `ssl: true` or an `ssl` object without `rejectUnauthorized: false`, a password set, no `ssl.ca` provided, and `client_ed25519` as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA.\n\n### Resolution\n`Ed25519PasswordAuth.hash()` now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests.\n\nFixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later.\n\n### Workarounds\nProvide the server certificate to the client (`ssl: { ca: ... }`) so standard certificate validation is used instead of fingerprint validation, or set `ssl: { rejectUnauthorized: false }` to opt into trust mode, or use an authentication plugin other than `client_ed25519`, until upgraded.\n\n### Credit\nReported by fg0x0.",
  "id": "GHSA-cx2f-j9fh-8g68",
  "modified": "2026-10-08T19:42:04Z",
  "published": "2026-10-08T19:42:04Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4"
    },
    {
      "type": "WEB",
      "url": "https://jira.mariadb.org/browse/CONJS-356"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS"
}

GHSA-CX8W-R23V-JMJV

Vulnerability from github – Published: 2024-10-29 18:30 – Updated: 2024-10-29 18:30
VLAI
Details

Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-26586"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-248"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-02-14T14:15:44Z",
    "severity": "MODERATE"
  },
  "details": "Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.",
  "id": "GHSA-cx8w-r23v-jmjv",
  "modified": "2024-10-29T18:30:33Z",
  "published": "2024-10-29T18:30:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26586"
    },
    {
      "type": "WEB",
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.