Junglewise Threat Intelligence

CVE-2026-44172: MariaDB libmariadb SQL injection in mysql_real_escape_string using big5

CVE-2026-44172 · Severity: low · CVSS 3.1 · Published 2026-06-12

Vendors: Mariadb, PyPI.

Executive brief

A vulnerability in the MariaDB database connector library could allow attackers to bypass security filters and perform unauthorized database actions. When an application uses the 'big5' character set, the standard security function meant to clean user input fails to properly neutralize malicious commands. This could lead to unauthorized data access or modification in applications that rely on this specific configuration.

Technical details

A SQL injection vulnerability exists in MariaDB Connector/C (libmariadb) versions 3.3.18 and 3.4.8. The root cause is an improper implementation of the mysql_real_escape_string() function when processing the 'big5' multi-byte character set. An attacker can provide specially crafted input that exploits character encoding discrepancies to 'consume' the escape character, allowing subsequent malicious SQL commands to be executed. This affects applications using the text protocol and big5 encoding that do not use prepared statements. The issue is resolved in versions 3.3.19 and 3.4.9.

Affected products

  • MariaDB libmariadb 3.3.18, 3.4.8

Timeline

  • 2026-04-21: disclosed: Issue reported in MariaDB Jira
  • 2026-05-18: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References