MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-297"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107819.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107819.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "249726968211302489602923545727773800479",
"length": 1272
},
"id": "CVE-2026-107819-4394f37e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/mariadb-corporation/mariadb-connector-c/commit/8153da40fe720b1d25db12aa3f993918da15bd3b",
"target": {
"file": "unittest/libmariadb/ps.c",
"function": "test_vector"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"335824217201172825678247368787400597043",
"117583078661513530238598940099431934653",
"333449155896468801820679162423656675592"
],
"threshold": 0.9
},
"id": "CVE-2026-107819-e75aa4dc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mariadb-corporation/mariadb-connector-c/commit/8153da40fe720b1d25db12aa3f993918da15bd3b",
"target": {
"file": "unittest/libmariadb/ps.c"
}
}
]
"2026-10-10T07:06:00Z"