THREAT OPS › Threat News › [GHSA] GHSA-g9jj-cgmh-9f38 (medium) — MariaDB has cleartext password disclosure to a MITM on the initial-handshake
[GHSA] GHSA-g9jj-cgmh-9f38 (medium) — MariaDB has cleartext password disclosure to a MITM on the initial-handshake
GHSA-g9jj-cgmh-9f38 Severity: medium CVE: CVE-2026-55856
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
### Summary
When a Java application connects with sslMode=verify-full (or verify-ca) and a password but does not pin a server certificate, Connector/J deliberately accepts an untrusted/self-signed certificate at the TLS layer (the "MITM-proof without a CA" featur
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55856cve
Original source: https://github.com/advisories/GHSA-g9jj-cgmh-9f38