VYPR
Medium severity4.4NVD Advisory· Published Oct 9, 2026

CVE-2026-107817

CVE-2026-107817

Description

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contained valid MySQL binary JSON data. A specially prepared MySQL table containing invalid JSON data could cause out-of-bounds reads, information disclosure, or a server crash. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.

Affected products

1
  • MariaDB/Serverllm-fuzzy
    Range: 10.6.1 - 10.6.27, 10.11.1 - 10.11.18, 11.4.1 - 11.4.12, 11.8.1 - 11.8.8, 12.3.1 - 12.3.2, 13.0.1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.