GHSA-48qf-xh34-q73r

Suggest an improvement
Source
https://github.com/advisories/GHSA-48qf-xh34-q73r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-48qf-xh34-q73r/GHSA-48qf-xh34-q73r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-48qf-xh34-q73r
Aliases
  • CVE-2026-107383
Published
2026-10-08T19:42:11Z
Modified
2026-10-08T20:00:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
Details

Description

When encoding a GeoJSON Polygon or MultiPolygon parameter for the binary protocol, the connector sized its output buffer from the length property of each ring, then wrote each ring only if it was a real array. The two loops disagreed: any non-array ring carrying a numeric length (a string, or an object such as {"length": 4000}) still reserved 4 + 16 * length bytes, but wrote none of them. The buffer came from Buffer.allocUnsafe() and was returned in full regardless of how far the write position had advanced, so every reserved-but-unwritten byte was uninitialized Node.js heap.

The sibling LineString case handled this correctly, aborting with null on the first malformed point, so no reserved byte could escape unwritten.

The only gate on this path is value.type naming a GeoJSON type, so any object shaped like {"type": "Polygon", ...} reached the encoder.

Impact

An application that passes an attacker-influenced object as a parameter to execute() or batch() writes uninitialized process memory into the database, where it is readable by anyone who can read that row and persists into backups and replicas. Applications accepting GeoJSON for map or location features are the natural case, as the attacker controls coordinates directly.

The disclosed memory is not scoped to the requesting user: in a shared Node.js process the heap may hold other users' request and response bodies, session tokens and cookies, database credentials and TLS key material. The leak is silent — the insert succeeds and the column simply holds more bytes than it should.

No non-default connector option and no particular server configuration are required. query() is not affected: the text encoder builds geometry as strings rather than through Buffer.allocUnsafe().

Resolution

Both the Polygon and MultiPolygon encoders now reject a non-array ring before reserving space for it, so no byte of the allocation can be left uninitialized by the writing loop, matching the existing LineString behaviour.

Workarounds Validate that GeoJSON coordinates are properly nested arrays of numbers before passing the object as a parameter, or use query(), until upgraded.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T19:42:11Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / mariadb

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.2.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-48qf-xh34-q73r/GHSA-48qf-xh34-q73r.json"

npm / mariadb

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.3.0
Fixed
3.3.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-48qf-xh34-q73r/GHSA-48qf-xh34-q73r.json"

npm / mariadb

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.4.0
Fixed
3.4.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-48qf-xh34-q73r/GHSA-48qf-xh34-q73r.json"

npm / mariadb

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.5.0-rc.0
Fixed
3.5.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-48qf-xh34-q73r/GHSA-48qf-xh34-q73r.json"