{"id":"AZL-105179","summary":"CVE-2026-89136 affecting package mariadb 10.11.19-1","details":"When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and only enabled in --enable-rpk OR --enable-all OR --enable-distro AKA HAVE_RPK builds.","modified":"2026-10-02T05:34:59Z","published":"2026-09-27T10:16:59Z","upstream":["CVE-2026-89136"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89136"}],"affected":[{"package":{"name":"mariadb","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/mariadb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"10.11.19-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105179.json"}}],"schema_version":"1.9.0"}