High severity8.5NVD Advisory· Published Mar 20, 2026· Updated Mar 31, 2026
CVE-2026-32710
CVE-2026-32710
Description
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/MariaDB/server/security/advisories/GHSA-4rj5-2227-9wgcnvdVendor Advisory
- jira.mariadb.org/browse/MDEV-38356nvdVendor AdvisoryIssue Tracking
News mentions
1- DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the ProxyCheck Point Research · Apr 20, 2026