GHSA-r3rv-jm3r-62q2: SQL Injection

Published Oct 8, 2026
·
Updated

Description When escaping string and binary parameters for the text protocol, the connector always escaped the quote character with a backslash, without ever consulting the session's NOBACKSLASHESCAPES SQL mode. The server status flag was declared (STATUSNOBACKSLASHESCAPES) but never read.

Under a server or session running with NOBACKSLASHESCAPES, the backslash is an ordinary character and the quote must be escaped by doubling it. The escaped value produced by the connector therefore closed the string literal, and a value passed through a placeholder was interpreted as SQL.

All text-protocol escaping entry points were affected, including Connection.escape().

Impact An attacker able to influence any value the application passes as a query parameter could execute arbitrary SQL with the privileges of the application's database user: read, modify or delete any data reachable by that connection.

Exposure requires a deployment where NOBACKSLASHESCAPES is enabled — server-wide, through the connector's sessionVariables / initSql options, or by an application-issued SET sqlmode. It is not implied by the ANSI, ORACLE or TRADITIONAL compound modes on MariaDB 11.4, so it has to be set deliberately. Where it is enabled, no unusual application code is needed: the standard placeholder API is the injection point.

execute() and batch() are not affected: the binary prepared-statement and bulk protocols send parameter values out of band.

Resolution The escaping routines now branch on the session status flag, doubling the quote and leaving the backslash untouched when NOBACKSLASHESCAPES is set

Workarounds Use execute() or batch(), or do not enable NOBACKSLASHESCAPES, until upgraded.

Credit Reported by fg0x0.

Affected Software

4 affected componentsFixes available
npm/mariadb>=3.5.0-rc.0<3.5.4
3.5.4
npm/mariadb>=3.4.0<3.4.7
3.4.7
npm/mariadb>=3.3.0<3.3.4
3.3.4
npm/mariadb<3.2.5
3.2.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.5.4
  2. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.4.7
  3. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.3.4
  4. Upgrade

    Upgrade npm/mariadb to a version that resolves this vulnerability.

    Fixed in 3.2.5
  5. Configuration

    Do not enable NO_BACKSLASH_ESCAPES server-wide, through connector sessionVariables/initSql options, or via an application-issued SET sql_mode.

    MariaDB SQL mode NO_BACKSLASH_ESCAPES = disabled
  6. Compensating control

    Use execute() or batch() for parameterized operations until the connector is upgraded; these use binary prepared-statement and bulk protocols that send parameter values out of band.

Event History

Oct 8, 2026
Advisory Published
via GitHub·07:42 PM
Data Sourced
via GitHub·07:42 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

How can I determine whether an application connection is in the affected state?

Check whether NO_BACKSLASH_ESCAPES is enabled server-wide or for the affected session. Also review connector sessionVariables and initSql options, and application code that issues SET sql_mode.

2

Do the ANSI, ORACLE, or TRADITIONAL compound SQL modes enable the vulnerable behavior?

On MariaDB 11.4, those compound modes do not imply NO_BACKSLASH_ESCAPES. Exposure still requires NO_BACKSLASH_ESCAPES to be enabled separately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203