THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g5xc-5w98-jfvm (medium) — MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets

[GHSA] GHSA-g5xc-5w98-jfvm (medium) — MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets

medgithub_advisoriesPublished 2026-08-28

GHSA-g5xc-5w98-jfvm Severity: medium CVE: CVE-2026-55855

MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets

### Summary

A SQL injection is possible when the connector escapes Buffer parameters client-side under a multi-byte client character set whose trail-byte range overlaps the ASCII backslash (0x5C): big5, gbk, sjis, cp932, and

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g5xc-5w98-jfvm