Listen to this Post
On the zero-configuration TLS path, the MariaDB Node.js connector accepts a self-signed server certificate at the TLS level and subsequently attempts to validate the server’s identity using the fingerprint hash appended to the final OK_Packet via Authentication.validateFingerPrint. This validation logic calls hash() on the active authentication plugin to compute the password-derived secret combined with the seed and certificate fingerprint. Within Ed25519PasswordAuth.hash(), the code references an identifier seed that is completely out of scope—neither a method parameter nor a module-scope binding—existing solely as a parameter of an unrelated static encryptPassword method. Consequently, executing this code throws a ReferenceError: seed is not defined synchronously inside the socket data handler. Because no error handler guards this frame between PacketInputStream.onData() and the plugin, the error escapes as an uncaught exception, terminating the client process and creating an availability-only denial of service vector.
DailyCVE Form:
Platform: MariaDB Connector/Node.js
Version: 3.3.0 to 3.5.4
Vulnerability : Uncaught Exception DoS
Severity : Medium
date: October 8, 2026
Prediction: September 2026
What Undercode Say:
bash commands and codes:
npm install [email protected]
const mariadb = require('mariadb');
const pool = mariadb.createPool({
host: 'localhost',
user: 'root',
password: 'secret',
ssl: true
});
Exploit: (Educational Purposes!)
An unauthenticated attacker or Man-in-the-Middle intercepting a TCP connection with a self-signed certificate can force the client to negotiate ed25519 authentication and reply with an OK_Packet carrying a 0x01-prefixed validation hash. This triggers the out-of-scope seed reference error synchronously within the socket data handler, causing an uncaught exception that crashes the client Node.js process.
Protection: from this CVE
Upgrade MariaDB Connector/Node.js to version 3.5.4 or later. Alternatively, provide a trusted server certificate via ssl: { ca: … }, disable strict verification via ssl: { rejectUnauthorized: false }, use a Unix domain socket, or select an authentication plugin other than client_ed25519.
Impact:
Denial of service against the client process via application termination under Node’s default uncaughtException behavior. No credentials are disclosed and no database data is altered.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

