THREAT OPS › Threat News › [GHSA] GHSA-c857-9x2m-cvh2 (medium) — org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
[GHSA] GHSA-c857-9x2m-cvh2 (medium) — org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
GHSA-c857-9x2m-cvh2 Severity: medium CVE: CVE-2026-55860
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
### Summary
The connector does not gate clear-text password authentication plugins on transport encryption. A hostile or man-in-the-middle MariaDB server can request a clear-text plu
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55860cve
Original source: https://github.com/advisories/GHSA-c857-9x2m-cvh2