Inappropriate Encoding for Output Context Affecting org.mariadb.jdbc:mariadb-java-client package, versions [,2.7.14)[3.0.0,3.3.5)[3.4.0,3.4.3)[3.5.0,3.5.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGMARIADBJDBC-19428613
  • published29 Aug 2026
  • disclosed28 Aug 2026
  • creditfg0x0

Introduced: 28 Aug 2026

NewCVE-2026-55858  (opens in a new tab)
CWE-838  (opens in a new tab)

How to fix?

Upgrade org.mariadb.jdbc:mariadb-java-client to version 2.7.14, 3.3.5, 3.4.3, 3.5.9 or higher.

Overview

Affected versions of this package are vulnerable to Inappropriate Encoding for Output Context in the connection process. An attacker can cause silent data corruption and potentially bypass input sanitization by manipulating the character set mid-session, leading to a mismatch between client and server encoding interpretations.

CVSS Base Scores

version 4.0
version 3.1