• Sources: advisory, second advisory, release
  • Summary: Two GitHub advisories cover MariaDB Connector/R2DBC. One is cleartext password disclosure to a hostile server, tracked as CVE-2026-55860 at moderate severity and CVSS 5.9 under CWE-319 and CWE-522, affecting versions below 1.4.1 and patched in 1.4.1. The other is character set confusion applied mid-session, also fixed in 1.4.1. GHSA-c857-9x2m-cvh2 gives a workaround for anyone who cannot upgrade yet: supply the server or CA certificate and select a verifying SSL mode, so the transport is encrypted before credentials are sent.
  • Why it matters: An on-path attacker posing as the server can capture database passwords in cleartext from unpatched Connector/R2DBC clients.

send feedback on this story