{"id":"CVE-2026-107819","summary":"MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verification failure","details":"MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.","aliases":["GHSA-fmq9-qjxj-qpf7"],"modified":"2026-10-10T07:06:00.509190271Z","published":"2026-10-09T17:25:45.082Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-297"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107819.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107819.json"},{"type":"ADVISORY","url":"https://github.com/MariaDB/server/security/advisories/GHSA-fmq9-qjxj-qpf7"},{"type":"FIX","url":"https://github.com/mariadb-corporation/mariadb-connector-c/commit/e8c0a16d94ddf844668d684a7d42b37ac8e0fc02"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-c/releases/tag/v3.4.10"},{"type":"WEB","url":"https://jira.mariadb.org/browse/CONC-846"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107819"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mariadb-corporation/mariadb-connector-c","events":[{"introduced":"de6305915f86bb33c83b1fe782a2b8a76920aec1"},{"fixed":"8153da40fe720b1d25db12aa3f993918da15bd3b"}],"database_specific":{"extracted_events":[{"introduced":"3.4.1"},{"fixed":"3.4.10"}],"source":"AFFECTED_FIELD"}}],"versions":["v3.4.9","v3.4.7","v3.4.8","v3.4.6","v3.4.4","v3.4.3","v3.4.2","v3.4.1"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"length":1272,"function_hash":"249726968211302489602923545727773800479"},"id":"CVE-2026-107819-4394f37e","signature_type":"Function","signature_version":"v1","source":"https://github.com/mariadb-corporation/mariadb-connector-c/commit/8153da40fe720b1d25db12aa3f993918da15bd3b","target":{"function":"test_vector","file":"unittest/libmariadb/ps.c"}},{"target":{"file":"unittest/libmariadb/ps.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["335824217201172825678247368787400597043","117583078661513530238598940099431934653","333449155896468801820679162423656675592"]},"id":"CVE-2026-107819-e75aa4dc","signature_type":"Line","signature_version":"v1","source":"https://github.com/mariadb-corporation/mariadb-connector-c/commit/8153da40fe720b1d25db12aa3f993918da15bd3b"}],"vanir_signatures_modified":"2026-10-10T07:06:00Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107819.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}