Logo
vulnerabilityCVE-2026-32710
Name
CVE-2026-32710
Source
NVD ( link)Debian ( link)
Description
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mariadb
Exploitable

Vulnerability Ratings#


8.5
CVSSv31
9.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.11.17
Not Affected
buildroot
master
10.11.17
Not Affected
openwrt
master
3.4.8-r3
Not Affected
openwrt
master
11.8.3-r1
Exploitable
yocto
kirkstone
10.7.8
Not Affected
yocto
master
11.4.12
Not Affected
yocto
scarthgap
10.11.16
Not Affected