Critical severity9.8NVD Advisory· Published Jun 12, 2026· Updated Jun 16, 2026
CVE-2026-44172
CVE-2026-44172
Description
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- osv-coords14 versionspkg:bitnami/mariadbpkg:bitnami/mariadb-minpkg:bitnami/mysql-clientpkg:rpm/almalinux/mariadb-connector-cpkg:rpm/almalinux/mariadb-connector-c-configpkg:rpm/almalinux/mariadb-connector-c-develpkg:rpm/almalinux/mariadb-connector-c-docpkg:rpm/almalinux/mariadb-connector-c-testpkg:rpm/opensuse/mariadb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/mariadb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/mariadb&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
>= 3.3.18, < 10.4.34+ 13 more
- (no CPE)range: >= 3.3.18, < 10.4.34
- (no CPE)range: >= 3.3.18, < 10.6.23
- (no CPE)range: >= 3.3.18, < 10.6.17
- (no CPE)range: < 3.4.4-2.el10_2
- (no CPE)range: < 3.4.4-2.el10_2
- (no CPE)range: < 3.4.4-2.el10_2
- (no CPE)range: < 3.4.4-2.el10_2
- (no CPE)range: < 3.4.4-2.el10_2
- (no CPE)range: < 11.8.8-160000.1.1
- (no CPE)range: < 11.8.7-1.1
- (no CPE)range: < 11.8.8-150700.3.15.1
- (no CPE)range: < 11.8.8-150700.3.15.1
- (no CPE)range: < 11.8.8-160000.1.1
- (no CPE)range: < 11.8.8-160000.1.1
Patches
Vulnerability mechanics
References
2- github.com/MariaDB/server/security/advisories/GHSA-pv9p-5w55-55jmnvdMitigationVendor Advisory
- jira.mariadb.org/browse/CONC-819nvdThird Party Advisory
News mentions
0No linked articles in our index yet.