CVE-2026-44172
published 2026-06-12CVE-2026-44172: MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.32%
23.7th percentile
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | — | — |
| mariadb | mariadb | — | — |
| mariadb | mariadb | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb_10.11 | mariadb | — | — |
| mariadb_11.8 | mariadb | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | mariadb | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.8CRITICAL
vendor_ubuntu8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MariaDB Server 3.3.18/3.4.8 mysql_real_escape_string sql injection (GHSA-pv9p-5w55-55jm / EUVD-2026-36517)
vuldb·2026-06-12·CVSS 6.9
CVE-2026-44172 [MEDIUM] MariaDB Server 3.3.18/3.4.8 mysql_real_escape_string sql injection (GHSA-pv9p-5w55-55jm / EUVD-2026-36517)
A vulnerability was found in MariaDB Server 3.3.18/3.4.8. It has been declared as critical. This impacts the function mysql_real_escape_string. The manipulation results in sql injection.
This vulnerability was named CVE-2026-44172. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Ubuntu
MariaDB vulnerabilities
vendor_ubuntu·2026-07-14·CVSS 8.0
CVE-2026-49261 [HIGH] MariaDB vulnerabilities
Title: MariaDB vulnerabilities
Summary: Several security issues were fixed in MariaDB.
It was discovered that MariaDB did not properly validate parameters
supplied by a joiner node during a State Snapshot Transfer using the
mariabackup method. An attacker could possibly use this issue to execute
arbitrary shell commands on the donor node. (CVE-2026-44168)
It was discovered that MariaDB did not properly enforce the SHOW CREATE
ROUTINE privilege when a user obtained access to a stored routine via a
role. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-44169)
It was discovered that MariaDB's mbstream utility did not properly validate
paths when unpacking archives. An attacker could possibly use this issue to
write files outside of the intende
Red Hat
mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
vendor_redhat·2026-06-12·CVSS 9.8
CVE-2026-44172 [CRITICAL] CWE-89 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
A flaw was found in MariaDB server. An application processing non-validated user input, which then uses `mysql_real_escape_string()` and sends data to the database via text protocol with the big5 character set, is vulnerable to SQL injection
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [epel-all]
bugzilla·2026-07-02·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [epel-all]
CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 a
Bugzilla
CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
bugzilla·2026-07-02·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
CVE-2026-44172 proxysql: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19
Bugzilla
CVE-2026-44172 mariadb-connector-c: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
bugzilla·2026-07-02·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 mariadb-connector-c: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
CVE-2026-44172 mariadb-connector-c: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in vers
Bugzilla
CVE-2026-44172 mariadb11.8: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
bugzilla·2026-06-30·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 mariadb11.8: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
CVE-2026-44172 mariadb11.8: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3
Bugzilla
CVE-2026-44172 mariadb10.11: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
bugzilla·2026-06-30·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 mariadb10.11: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
CVE-2026-44172 mariadb10.11: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.
Bugzilla
CVE-2026-44172 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
bugzilla·2026-06-12·CVSS 9.8
CVE-2026-44172 [CRITICAL] CVE-2026-44172 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
CVE-2026-44172 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.
https://github.com/MariaDB/server/security/advisories/GHSA-pv9p-5w55-55jmhttps://jira.mariadb.org/browse/CONC-819https://access.redhat.com/errata/RHSA-2026:30135https://access.redhat.com/security/cve/CVE-2026-44172https://bugzilla.redhat.com/show_bug.cgi?id=2488459https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44172.json
2026-06-12
Published