- Sources: advisory, issue tracker
- Summary: GitHub advisory GHSA-g5xc-5w98-jfvm, tracked as CVE-2026-55855, states that MariaDB Connector/Node.js allows SQL injection through Buffer parameters when the client character set is big5, gbk, sjis, cp932 or gb18030. The affected ranges are below 3.2.4, 3.3.0 up to 3.3.3, 3.4.0 up to 3.4.6, and 3.5.0 up to 3.5.3. Two conditions bound the exposure: none of the five character sets is the default, which is utf8mb4, and parameters bound through server-side prepared statements are unaffected because they are never escaped into SQL text.
- Why it matters: Applications on one of those five client charsets that bind untrusted data as Buffer parameters through client-side escaping are injectable until the connector is patched.
- Follow-up: The advisory sidebar lists 3.3.4 as the patched 3.3.x release while the description gives 3.3.3, so the fixed version on that branch needs confirming against the connector's own release notes.
send feedback on this story