CVE-2026-32710

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:12.1.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-20 19:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32710

Mitre link : CVE-2026-32710

CVE.ORG link : CVE-2026-32710


JSON object : View

Products Affected

mariadb

  • mariadb
CWE
CWE-122

Heap-based Buffer Overflow