wid-sec-w-2026-0815
·
Published 2026-03-22
·
View on BSI CERT-Bund ↗
MariaDB: Vulnerability allows Denial of Service and potenziell Code execution
CVSS 8.5
HIGH
Risk Summary
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
CVEs (1)
Affected Vendors
MariaDB
Affected Products (6)
MariaDB
·
MariaDB
Server <11.4.10
MariaDB
·
MariaDB
Server 11.4.10
MariaDB
·
MariaDB
Server <11.8.6
MariaDB
·
MariaDB
Server 11.8.6
MariaDB
·
MariaDB
Server <12.2.2
MariaDB
·
MariaDB
Server 12.2.2
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more