Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10. | |
| Title | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verification failure | |
| Weaknesses | CWE-297 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T17:25:45.082Z
Reserved: 2026-10-08T21:23:59.823Z
Link: CVE-2026-107819
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-297
Improper Validation of Certificate with Host Mismatch