{"id":"AZL-105191","summary":"CVE-2026-89135 affecting package mariadb 10.11.19-1","details":"A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS && !WOLFCRYPT_ONLY) defined or built with --enable-opensslextra and the application is specifically making calls to the X509_verify_cert function.","modified":"2026-10-01T14:15:49.996840923Z","published":"2026-09-27T10:16:59Z","upstream":["CVE-2026-89135"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89135"}],"affected":[{"package":{"name":"mariadb","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/mariadb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"10.11.19-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105191.json"}}],"schema_version":"1.9.0"}