Insufficiently Protected Credentials Affecting mariadb package, versions <3.5.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (36th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MARIADB-19432138
  • published30 Aug 2026
  • disclosed28 Aug 2026
  • creditUnknown

Introduced: 28 Aug 2026

NewCVE-2026-55215  (opens in a new tab)
CWE-295  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade mariadb to version 3.5.3 or higher.

Overview

Affected versions of this package are vulnerable to Insufficiently Protected Credentials in the authentication. An attacker can intercept sensitive credentials by performing a man-in-the-middle attack during the initial handshake.

Note: This is only exploitable if SSL/TLS is enabled without providing a CA or server certificate and the connection relies solely on fingerprint validation.

Workaround

This vulnerability can be mitigated by explicitly configuring certificate verification, providing the server/CA certificate, and using a verifying SSL mode such as VERIFY_CA or VERIFY_FULL.

CVSS Base Scores

version 4.0
version 3.1