CVE-2026-55855 | MariaDB Connector/Node.js up to 3.2.3/3.3.2/3.4.5/3.5.2 Packet Output Stream packet-output-stream.js PacketOutputStream.writeBufferEscape Buffer sql injection

SecurityVulns

A vulnerability was found in MariaDB Connector and Node.js up to 3.2.3/3.3.2/3.4.5/3.5.2. It has been classified as critical. Affected by this issue is the function PacketOutputStream.writeBufferEscape of the file lib/io/packet-output-stream.js of the component Packet Output Stream. The manipulation of the argument Buffer leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-55855. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More