Vulnerability Description
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a specially crafted archive could have caused mbstream to create files outside of the target-dir path. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | >= 10.6.1, < 10.6.26 |
Related Weaknesses (CWE)
References
- https://github.com/MariaDB/server/security/advisories/GHSA-9pjh-5hhw-65v9Vendor Advisory
- https://jira.mariadb.org/browse/MDEV-39408Issue TrackingThird Party Advisory
FAQ
What is CVE-2026-44171?
CVE-2026-44171 is a vulnerability with a CVSS score of 6.3 (MEDIUM). MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstrea...
How severe is CVE-2026-44171?
CVE-2026-44171 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44171?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb.