BIT-mysql-client-2026-35549

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mysql-client/BIT-mysql-client-2026-35549.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mysql-client-2026-35549
Aliases
Published
2026-06-05T05:51:29.789Z
Modified
2026-06-05T07:56:27.869021474Z
Summary
[none]
Details

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the cachingsha2password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256cryptr uses alloca.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mysql-client

Package

Name
mysql-client
Purl
pkg:bitnami/mysql-client

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.4.10
Introduced
11.5.0
Fixed
11.8.6
Introduced
12.0.0
Fixed
12.2.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/mysql-client/BIT-mysql-client-2026-35549.json"