Heap-based buffer overflow in MariaDB - CVE-2026-32710
Published: April 28, 2026
MariaDB
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the JSON_SCHEMA_VALID() function when processing crafted input. A remote user can send specially crafted input to execute arbitrary code.
Successful code execution requires tight control over memory layout and is generally only attainable in a lab environment.