THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cqhc-2h57-wpxf (high) — MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`

[GHSA] GHSA-cqhc-2h57-wpxf (high) — MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`

medgithub_advisoriesPublished 2026-08-28

GHSA-cqhc-2h57-wpxf Severity: high CVE: CVE-2026-55215

MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`

### Summary When SSL/TLS is enabled but no CA / server certificate is provided, the connector verifies the server's identity using fingerprint validation. The check is effective, the connection is ultimately rejected when it fails, but it happens *after* the au

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cqhc-2h57-wpxf