CVE-2026-44172 (matched: mariadb)

  • Friday, 31st July, 2026
  • 16:05pm

A security vulnerability has been identified in specific versions of MariaDB, a popular open-source database software used to power many websites. The flaw affects MariaDB versions 3.3.18 and 3.4.8.

Under specific conditions, attackers could bypass a common security tool that websites use to block harmful database commands. This occurs when a site accepts unvetted user input, uses that standard cleaning tool before sending data to the database, and connects to the database using the big5 character set and text protocol. If exploited, this could let bad actors access, modify, or delete your site's stored data, including user information and published content.

The issue has already been fixed in updated MariaDB versions 3.3.19 and 3.4.9.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-44172

« Back