![]() |
|
HackerOne Disclosed Reports - 2026-10-07 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-10-07 (/Thread-HackerOne-Disclosed-Reports-2026-10-07) |
HackerOne disclosed reports - 2026-10-07 - hashXploiter - 10-08-2026
Medium
resolved MariaDB HandlerSocket Improper Request Field-Count Validation Causes Server CrashBug reported by XlabAITeam was disclosed at October 7, 2026, 8:03 pm | Uncontrolled Resource Consumption A vulnerability was discovered in MariaDB Server's optional HandlerSocket plugin that allowed improper validation of request field-count parameters. When processing exec requests, the plugin allocated stack memory based on a client-supplied field count before validating whether the count was reasonable. An attacker could send requests with abnormally large field counts to cause the MariaDB process to crash, resulting in database service denial of service. The vulnerability affected deployments with HandlerSocket enabled, and could be exploited by unauthenticated attackers if no authentication secret was configured.
Medium
resolved MariaDB Low-Privilege User Can Exhaust Memory Through a Formatting Function and Crash the ServiceBug reported by XlabAITeam was disclosed at October 7, 2026, 8:01 pm | Uncontrolled Resource Consumption A low-privilege database user was able to exhaust memory on a MariaDB server through the SFORMAT() function by specifying an extremely large width parameter. The function attempted to allocate nearly 2 GB of memory before generating the return value. Multiple concurrent requests caused the database process to be terminated by the system's out-of-memory mechanism, resulting in service unavailability. The vulnerability required only basic database login privileges and the ability to execute standard SELECT queries. No administrative access, table privileges, or user interaction was necessary to exploit this denial-of-service condition.
High
resolved DROP PACKAGE leaves PACKAGE BODY grant in mysql.procs_priv causing privilege escalationBug reported by jeb was disclosed at October 7, 2026, 7:57 pm | Improper Access Control - Generic A privilege escalation vulnerability was discovered in package management functionality. When a package was dropped, the associated grant in the privilege table for the package body was not removed, while the package object itself was deleted from the system catalog. If a new package with the same name was subsequently created, the orphaned grant allowed previous users to execute the new package without explicit authorization, running with the new definer's privileges. The vulnerability also propagated through role-based access control to all role members. The issue was specific to package drops, as other similar drop operations correctly cleaned up their respective privilege rows.
Medium
resolved Pre-authentication `size_t` integer underflow → out-of-bounds read / server crash in MariaDB `caching_sha2_password` (auth_mysql_sha2) via an RSA-OAEPBug reported by vnth4nhnt was disclosed at October 7, 2026, 7:54 pm | Integer Underflow A pre-authentication integer underflow vulnerability was discovered in the caching_sha2_password authentication plugin. When a client sent an RSA-OAEP encrypted empty message over plaintext TCP, the decrypted length was not validated before being used in a subtraction operation. This caused a size_t integer underflow that resulted in an out-of-bounds read in the SHA-256 hashing routine. The vulnerability allowed an unauthenticated attacker to crash the database server without requiring valid credentials.
High
resolved Missing FILE-privilege enforcement in CONNECT file UDFs allows server-side file read and writeBug reported by Duong Tran was disclosed at October 7, 2026, 7:53 pm | Improper Access Control - Generic A privilege enforcement vulnerability was discovered in file user-defined functions (UDFs) of a database engine. The file UDFs failed to enforce FILE privilege requirements and secure file path restrictions that were already implemented in the file-backed table handler. This allowed users with only SELECT privileges to read arbitrary files accessible to the database process and write files outside the configured secure directory. The vulnerability affected multiple file-related UDFs and was reproducible on multiple versions of the database software. The issue resulted from file UDFs not performing the same access control checks that were already in place for equivalent table operations.
Critical
resolved Low-privilege RCE in MariaDB: SYS_REFCURSOR cursor-array use-after-free chained with an ST_Area heap over-readBug reported by Rick de Jager was disclosed at October 7, 2026, 7:47 pm | Use After Free A critical remote code execution vulnerability was discovered in MariaDB Server 13.0.2. The vulnerability chained two memory-safety bugs to allow an authenticated low-privilege user to execute arbitrary operating system commands as the database process user without requiring FILE, SUPER, or administrative privileges.
High
resolved Heap Use-After-Free in Materialized_cursor::open via SYS_REFCURSOR Array ReallocationBug reported by Akhil Koul was disclosed at October 7, 2026, 7:46 pm | Use After Free A heap-use-after-free vulnerability was identified in the cursor handling mechanism of the database server. The vulnerability existed in the cursor opening function where array reallocation during nested cursor operations caused dangling pointer references. When a cursor's SELECT statement invoked a function that opened additional cursors, the underlying memory buffer was reallocated, invalidating previously stored pointer addresses. These stale pointers were subsequently used for virtual method calls and memory writes, resulting in potential code execution and heap corruption. The issue affected authenticated users with function creation privileges and was distinct from a previously addressed related bug that had removed a stored member variable but had not corrected the parameter passing at the call site. |