CVE-2026-107383: MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters

Published Oct 8, 2026
·
Updated

Description When encoding a GeoJSON Polygon or MultiPolygon parameter for the binary protocol, the connector sized its output buffer from the length property of each ring, then wrote each ring only if it was a real array. The two loops disagreed: any non-array ring carrying a numeric length (a string, or an object such as {"length": 4000}) still reserved 4 + 16 length bytes, but wrote none of them. The buffer came from Buffer.allocUnsafe() and was returned in full regardless of how far the write position had advanced, so every reserved-but-unwritten byte was uninitialized Node.js heap.

The sibling LineString case handled this correctly, aborting with null on the first malformed point, so no reserved byte could escape unwritten.

The only gate on this path is value.type naming a GeoJSON type, so any object shaped like {"type": "Polygon", ...} reached the encoder.

Impact An application that passes an attacker-influenced object as a parameter to execute() or batch() writes uninitialized process memory into the database, where it is readable by anyone who can read that row and persists into backups and replicas. Applications accepting GeoJSON for map or location features are the natural case, as the attacker controls coordinates directly.

The disclosed memory is not scoped to the requesting user: in a shared Node.js process the heap may hold other users' request and response bodies, session tokens and cookies, database credentials and TLS key material. The leak is silent — the insert succeeds and the column simply holds more bytes than it should.

No non-default connector option and no particular server configuration are required. query() is not affected: the text encoder builds geometry as strings rather than through Buffer.allocUnsafe().

Resolution Both the Polygon and MultiPolygon encoders now reject a non-array ring before reserving space for it, so no byte of the allocation can be left uninitialized by the writing loop, matching the existing LineString behaviour.

Workarounds Validate that GeoJSON coordinates are properly nested arrays of numbers before passing the object as a parameter, or use query(), until upgraded.

Other sources

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

— MITRE

Affected Software

5 affected componentsFixes available
npm/mariadb<3.2.5, <3.3.4, <3.4.7, <3.5.4
npm/mariadb>=3.5.0-rc.0<3.5.4
3.5.4
npm/mariadb>=3.4.0<3.4.7
3.4.7
npm/mariadb>=3.3.0<3.3.4
3.3.4
npm/mariadb<3.2.5
3.2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.5.4
  2. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.4.7
  3. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.3.4
  4. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.2.5
  5. Upgrade

    Upgrade MariaDB Connector/Node.js to a version that resolves this vulnerability.

    Fixed in 3.2.5
  6. Upgrade

    Upgrade MariaDB Connector/Node.js to a version that resolves this vulnerability.

    Fixed in 3.3.4
  7. Upgrade

    Upgrade MariaDB Connector/Node.js to a version that resolves this vulnerability.

    Fixed in 3.4.7
  8. Upgrade

    Upgrade MariaDB Connector/Node.js to a version that resolves this vulnerability.

    Fixed in 3.5.4
  9. Compensating control

    Before passing GeoJSON as a parameter, validate that coordinates are properly nested arrays of numbers; alternatively use query(), whose text-protocol path is not affected, until upgrading.

Event History

Oct 8, 2026
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·07:42 PM
Data Sourced
via GitHub·07:42 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using the MariaDB Connector/Node.js affected versions are exposed only when they encode GeoJSON Polygon or MultiPolygon values through execute() or batch(). The text-protocol query() path is not affected.

2

What does an attacker need to do to trigger the disclosure?

An attacker needs to cause the application to submit malformed GeoJSON in which a Polygon or MultiPolygon ring is a non-array. The vulnerable binary encoder can then send uninitialized Node.js heap bytes as part of the database value.

3

Which versions contain the fix?

Upgrade to 3.2.5, 3.3.4, 3.4.7, or 3.5.4, as appropriate for the version line in use. Versions prior to those releases are affected.

4

What should be done if upgrading cannot happen immediately?

Avoid passing untrusted GeoJSON Polygon or MultiPolygon data to execute() or batch(), and validate that every ring is an array before it reaches the connector. The query() text-protocol path is not affected.

5

What data may need investigation after exposure?

Review GeoJSON values persisted through the affected paths, along with downstream backups and replicas, because leaked heap data may have been stored and propagated. The disclosed contents can include other users' content, session material, database credentials, or TLS key material.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203