THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c857-9x2m-cvh2 (medium) — org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)

[GHSA] GHSA-c857-9x2m-cvh2 (medium) — org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)

medgithub_advisoriesPublished 2026-08-28

GHSA-c857-9x2m-cvh2 Severity: medium CVE: CVE-2026-55860

org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)

### Summary

The connector does not gate clear-text password authentication plugins on transport encryption. A hostile or man-in-the-middle MariaDB server can request a clear-text plu

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c857-9x2m-cvh2