Security Advisory

CVE-2026-44172

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-12 17:34:04
Last updated 2026-07-23 12:08:08
Assigner GitHub_M
CVSS score 6.9
State PUBLISHED

Description

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.