VYPR

apk package

chainguard/debezium-3.6-connector-mariadb

pkg:apk/chainguard/debezium-3.6-connector-mariadb

Vulnerabilities (4)

  • CVE-2026-55858MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set

  • CVE-2026-55857MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password pl

  • CVE-2026-55856MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCer

  • CVE-2026-59949MedAug 18, 2026
    affected < 3.6.1-r1fixed 3.6.1-r1

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFact