{"id":"GHSA-wxmm-q36w-r9xj","summary":"MariaDB Connector/J does not enforce allowLocalInfile=false  on server-initiated LOCAL INFILE requests","details":"## Summary\n\nMariaDB Connector/J does not enforce `allowLocalInfile=false` when \nprocessing server-initiated LOCAL INFILE requests (protocol packet \ntype `0xfb`). However, exploitation is constrained: the server can \nonly request the exact filename the client already included in its \n`LOAD DATA LOCAL INFILE` query, it cannot redirect to arbitrary paths.\n\n## Details\n\nWhen a client executes `LOAD DATA LOCAL INFILE '/path/to/file'`, the \nconnector sends the filename to the server as part of the COM_QUERY. \nA rogue or MitM server responds with a `0xfb` packet echoing that \nsame filename. The connector, without checking `allowLocalInfile`, \ntransmits the file content.\n\nThe bypass is therefore limited to the file the application itself \nintended to load. The attacker cannot escalate to other files \n(e.g. `/etc/passwd`) unless the application's own query targets them.\n\nThe real-world risk is:\n- An application that uses `LOAD DATA LOCAL INFILE` on potentially \n  sensitive files (credentials, exports, configs) and connects over \n  an untrusted network.\n- `allowLocalInfile=false` is supposed to disable this entire \n  mechanism as a defense-in-depth measure, but the flag is ignored.\n\n## Impact\n\nThe security guarantee of `allowLocalInfile=false` is not upheld, \nbut practical exploitation requires both a MitM/rogue server and an \napplication that actively uses LOCAL INFILE on sensitive data.\n\n## Credit\n\nReported by tharavel","aliases":["CVE-2026-61700"],"modified":"2026-09-17T16:45:06.489349270Z","published":"2026-09-17T16:29:53Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-09-17T16:29:53Z","nvd_published_at":null,"cwe_ids":["CWE-284"]},"references":[{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/security/advisories/GHSA-wxmm-q36w-r9xj"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/commit/0205d8be947918566cd9ce5a9db149541bbc8dee"},{"type":"PACKAGE","url":"https://github.com/mariadb-corporation/mariadb-connector-j"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/releases/tag/3.5.9"}],"affected":[{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.14"}]}],"versions":["1.1.10","1.1.7","1.1.8","1.1.9","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.0-beta-1","1.3.0-beta-2","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.4.0","1.4.0-beta-1","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.5.0-RC1","1.5.1-RC","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.8.0","2.0.0-RC","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.6.2","2.7.0","2.7.1","2.7.10","2.7.11","2.7.12","2.7.13","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.7.8","2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wxmm-q36w-r9xj/GHSA-wxmm-q36w-r9xj.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.3.5"}]}],"versions":["3.0.1-beta","3.0.10","3.0.11","3.0.2-rc","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wxmm-q36w-r9xj/GHSA-wxmm-q36w-r9xj.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.4.0"},{"fixed":"3.4.3"}]}],"versions":["3.4.0","3.4.1","3.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wxmm-q36w-r9xj/GHSA-wxmm-q36w-r9xj.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"3.5.9"}]}],"versions":["3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wxmm-q36w-r9xj/GHSA-wxmm-q36w-r9xj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}