THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g9jj-cgmh-9f38 (medium) — MariaDB has cleartext password disclosure to a MITM on the initial-handshake

[GHSA] GHSA-g9jj-cgmh-9f38 (medium) — MariaDB has cleartext password disclosure to a MITM on the initial-handshake

medgithub_advisoriesPublished 2026-08-28

GHSA-g9jj-cgmh-9f38 Severity: medium CVE: CVE-2026-55856

MariaDB has cleartext password disclosure to a MITM on the initial-handshake

### Summary

When a Java application connects with sslMode=verify-full (or verify-ca) and a password but does not pin a server certificate, Connector/J deliberately accepts an untrusted/self-signed certificate at the TLS layer (the "MITM-proof without a CA" featur

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g9jj-cgmh-9f38