THREAT OPS › Threat News › [GHSA] GHSA-cqhc-2h57-wpxf (high) — MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
[GHSA] GHSA-cqhc-2h57-wpxf (high) — MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
GHSA-cqhc-2h57-wpxf Severity: high CVE: CVE-2026-55215
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
### Summary When SSL/TLS is enabled but no CA / server certificate is provided, the connector verifies the server's identity using fingerprint validation. The check is effective, the connection is ultimately rejected when it fails, but it happens *after* the au
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55215cve
Original source: https://github.com/advisories/GHSA-cqhc-2h57-wpxf