MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cx2f-j9fh-8g68 | MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4. | |
| Title | MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS | |
| Weaknesses | CWE-248 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T18:42:37.155Z
Reserved: 2026-10-07T21:07:54.988Z
Link: CVE-2026-107382
No data.
Status : Awaiting Analysis
Published: 2026-10-08T19:17:00.590
Modified: 2026-10-08T20:25:00.647
Link: CVE-2026-107382
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:15:06Z
Weaknesses
Github GHSA