An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the cachingsha2password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256cryptr uses alloca.
{
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35549.json",
"cna_assigner": "mitre",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "11.4.10"
},
{
"introduced": "11.5.0"
},
{
"fixed": "11.8.6"
},
{
"introduced": "12.0.0"
},
{
"fixed": "12.2.2"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "11.4.10"
},
{
"introduced": "11.5.x"
},
{
"fixed": "11.8.x"
},
{
"fixed": "11.8.6"
},
{
"introduced": "12.x"
},
{
"fixed": "12.2.2"
}
],
"source": "DESCRIPTION"
}
]
}{
"cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "11.4.10"
},
{
"introduced": "12.0.0"
},
{
"fixed": "12.2.2"
},
{
"introduced": "11.5.0"
},
{
"fixed": "11.8.6"
}
],
"source": "CPE_RANGE"
}[
{
"signature_version": "v1",
"source": "https://github.com/mariadb/server/commit/d26a6f44c1f2119377e79a9540886c6d8c01472f",
"deprecated": false,
"target": {
"file": "sql/sp_instr.cc"
},
"id": "CVE-2026-35549-22eb6579",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"331495033010792057398295084692551616862",
"178889473583969224685848879336469251622",
"72995215509533274417683389386874442936",
"34733286214113447932010597917174327234",
"220595837734737098186096626766433509208",
"338750869998908232338240892716586972189",
"200331074068810549623743321810491183265",
"318528549273668054390962137954896768015",
"26834430279848683763735550481300098934",
"68590751291616411132278116452337632760",
"155245705888256277018230600879388905005",
"281201383801172153236642507346466029898",
"11578098737963444869029556637210276545",
"88679534638751502059684342659870334045",
"174412566811641505963715332693034819441",
"212479306865523010564552785282223352918",
"264094808494796852436130642367514195992"
]
}
},
{
"signature_version": "v1",
"source": "https://github.com/mariadb/server/commit/d26a6f44c1f2119377e79a9540886c6d8c01472f",
"deprecated": false,
"target": {
"file": "sql/sp_instr.h"
},
"id": "CVE-2026-35549-f170ab29",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"333736738574052575197108677744715005253",
"262810137784205432405179339402165348111",
"118178308854161151067014370856362614751",
"10257631431620263937293216233444103471"
]
}
},
{
"signature_version": "v1",
"source": "https://github.com/mariadb/server/commit/d26a6f44c1f2119377e79a9540886c6d8c01472f",
"deprecated": false,
"target": {
"file": "sql/sp_instr.cc",
"function": "sp_lex_instr::parse_expr"
},
"id": "CVE-2026-35549-fe069a50",
"signature_type": "Function",
"digest": {
"length": 2658.0,
"function_hash": "47421469537526624674199985998928255848"
}
}
]
"2026-07-27T08:14:24Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35549.json"