CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-35549: An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.

mediumCVSS 6.5CVE-2026-35549

CSIRTS triage

vendor: MariaDBproduct: MariaDB ServerDenial of serviceaffected: before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2
What
A large packet can crash the server if the caching_sha2_password authentication plugin is installed and user accounts are configured to use it.
Who is affected
MariaDB Server deployments with caching_sha2_password authentication plugin enabled and affected user accounts.
Urgency
Medium severity (CVSS 6.5); denial of service via authenticated crash, not currently exploited.
Action
Upgrade to MariaDB Server 11.4.10, 11.8.6, or 12.2.2 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch MariaDB Server

Get an email when a new MariaDB Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 6.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35549

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-35549coverage & exploitation statusNVD · CVE.org

Recent advisories for MariaDB Server

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center