CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-44172

Critical · CVSS 9.1

MariaDB Connector/C — SQL Injection via improper character escaping (big5 charset bypass of mysql_real_escape_string)

CVSS
9.1
nvd
EPSS
0.58%
44th pct
KEV
No
Class
kernel local
CWE-89, CWE-89

Description

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9.

Search profile — drives PoC discovery

Symbols mysql_real_escape_stringbig5text protocolCONC-819GHSA-pv9p-5w55-55jmmariadb_real_escape_string
Keywords CVE-2026-44172MariaDB SQL injectionmysql_real_escape_string big5 bypassbig5 charset SQL injectionMariaDB connector C escape bypassCONC-819GHSA-pv9p-5w55-55jmMariaDB 3.3.18 3.4.8 SQLi
Versions: 3.3.18, 3.4.8 (fixed in 3.3.19 and 3.4.9)

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z