GHSA-CX2F-J9FH-8G68
Vulnerability from github – Published: 2026-10-08 19:42 – Updated: 2026-10-08 19:42Description
On the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server's identity from the fingerprint hash the server appends to the final OK_Packet (Authentication.validateFingerPrint). That validation calls hash() on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint.
Ed25519PasswordAuth.hash() referenced an identifier seed that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static encryptPassword(password, seed). Invoking the method therefore threw ReferenceError: seed is not defined.
The throw happens synchronously inside the socket data handler, and no frame between PacketInputStream.onData() and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error.
Because the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully — the failure is not limited to a hostile server.
Impact
Denial of service against the client process. Under Node's default uncaughtException behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only.
An unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a 0x01-prefixed validation hash.
Exposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), ssl: true or an ssl object without rejectUnauthorized: false, a password set, no ssl.ca provided, and client_ed25519 as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA.
Resolution
Ed25519PasswordAuth.hash() now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests.
Fixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later.
Workarounds
Provide the server certificate to the client (ssl: { ca: ... }) so standard certificate validation is used instead of fingerprint validation, or set ssl: { rejectUnauthorized: false } to opt into trust mode, or use an authentication plugin other than client_ed25519, until upgraded.
Credit
Reported by fg0x0.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "mariadb"
},
"ranges": [
{
"events": [
{
"introduced": "3.3.0"
},
{
"fixed": "3.5.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-107382"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T19:42:04Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Description\nOn the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the server\u0027s identity from the fingerprint hash the server appends to the final OK_Packet (`Authentication.validateFingerPrint`). That validation calls `hash()` on the authentication plugin in use to obtain the password-derived secret both sides combine with the seed and the certificate fingerprint.\n\n`Ed25519PasswordAuth.hash()` referenced an identifier `seed` that was not in scope: it was neither a parameter of the method nor a module-scope binding, existing only as a parameter of the unrelated static `encryptPassword(password, seed)`. Invoking the method therefore threw `ReferenceError: seed is not defined`.\n\nThe throw happens synchronously inside the socket `data` handler, and no frame between `PacketInputStream.onData()` and the plugin guards it, so the error escapes as an uncaught exception rather than surfacing as a connection error.\n\nBecause the fingerprint hash is what a legitimate MariaDB server sends on this path, ed25519 authentication with zero-configuration TLS never completed successfully \u2014 the failure is not limited to a hostile server.\n\n### Impact\nDenial of service against the client process. Under Node\u0027s default `uncaughtException` behaviour the process exits, so a long-running service is terminated rather than seeing a failed connection attempt. No credential is disclosed and no data is altered; the impact is availability only.\n\nAn unauthenticated attacker able to intercept the connection (a MitM presenting a self-signed certificate, or a compromised server) can trigger the crash at will, since the self-signed-certificate path is precisely what such an attacker exercises and the rogue server only has to answer the ed25519 challenge with an OK_Packet carrying a `0x01`-prefixed validation hash.\n\nExposure requires all of the following: a MariaDB server reached over TCP (not a unix socket), `ssl: true` or an `ssl` object without `rejectUnauthorized: false`, a password set, no `ssl.ca` provided, and `client_ed25519` as the negotiated authentication plugin. Other authentication plugins are unaffected, as is any configuration where the server certificate is verified against a provided CA.\n\n### Resolution\n`Ed25519PasswordAuth.hash()` now returns the Ed25519 public key derived from the password scalar, which is the value the server combines into the fingerprint hash, and the derivation is covered by unit and integration tests.\n\nFixed in 3.5.4. The 3.3.x and 3.4.x maintenance branches are not patched; upgrade to 3.5.4 or later.\n\n### Workarounds\nProvide the server certificate to the client (`ssl: { ca: ... }`) so standard certificate validation is used instead of fingerprint validation, or set `ssl: { rejectUnauthorized: false }` to opt into trust mode, or use an authentication plugin other than `client_ed25519`, until upgraded.\n\n### Credit\nReported by fg0x0.",
"id": "GHSA-cx2f-j9fh-8g68",
"modified": "2026-10-08T19:42:04Z",
"published": "2026-10-08T19:42:04Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68"
},
{
"type": "WEB",
"url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915"
},
{
"type": "PACKAGE",
"url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs"
},
{
"type": "WEB",
"url": "https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4"
},
{
"type": "WEB",
"url": "https://jira.mariadb.org/browse/CONJS-356"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.