StackRadar

CVE-2026-3494

Medium

Advisory

Published 3 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,787 indexed, latest versions
Container images
142
deployed by those charts
Fix available
5 of 8
affected packages

MariaDB Server Audit Plugin Comment Handling Bypass

Carried by container images the latest versions of 153 of 17,787 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
mariadbdeb1:10.11.3-1, 1:10.11.4-1~deb12u1, 1:10.11.6-0+deb12u1, 1:10.11.7+maria~deb12+14 more1:10.11.18-0+deb12u1, 1:11.8.6-0+deb13u1114
mariadbbitnami10.6.12-2, 10.6.12-3, 10.11.4-1, 11.2.6-0+6 more10.6.2511
mariadbapk10.11.8-r0, 10.11.10-r0, 11.4.4-r1, 11.4.5-r0+2 more10.11.16-r0, 11.4.10-r09
mysql-clientbitnami10.6.11-1, 10.11.10-0, 12.0.2-010.6.253
MariaDBbitnami10.11.4, 11.3.2-510.6.252
mariadb-10.1deb1:10.1.47-0ubuntu0.18.04.1, 1:10.1.48-0ubuntu0.18.04.1no fix listed2
mariadb-10.6deb1:10.6.7-2ubuntu1, 1:10.6.28+maria~ubu2204no fix listed2
mariadb-10.3deb1:10.3.34-0ubuntu0.20.04.1no fix listed1
OSV records
ALPINE-CVE-2026-3494BIT-mariadb-2026-3494BIT-mysql-client-2026-3494DEBIAN-CVE-2026-3494UBUNTU-CVE-2026-3494
Also known as
BIT-mariadb-min-2026-3494

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-3494.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
mariadb@11.4.5-r2
11.4.10-r0

Open the chart page →

14,618
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-3494.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
mariadb@1:12.3.2+maria~ubu2404
no fix listed

Open the chart page →

4,032
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-3494.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
mariadb@1:12.3.3+maria~ubu2404
no fix listed

Open the chart page →

5,635

Container images carrying it

142 by charts deploying them

A fixed version is listed for 5 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
mariadb@1:12.3.3+maria~ubu2404
no fix listed
12
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
3
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
mariadb@11.4.5-2
10.6.25
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
mariadb@1:10.11.3-1
1:10.11.18-0+deb12u1
2
library/mariadb:12.0.2:12.0-noble607835cd628b
mariadb@1:12.0.2+maria~ubu2404
no fix listed
2
library/mariadb:11.4611a2fcc5fa7
mariadb@1:11.4.13+maria~ubu2404
no fix listed
2
library/mariadb:10.692e50059ea0a
mariadb-10.6@1:10.6.28+maria~ubu2204
no fix listed
2
library/mariadb:12.3.3ab1c3dd38194
mariadb@1:12.3.3+maria~ubu2404
no fix listed
2
library/python:3.7eedf63967cdb
mariadb@1:10.11.3-1
1:10.11.18-0+deb12u1
2
louislam/uptime-kuma:2.5.4917318f9d7be
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
mariadb@1:10.11.4-1~deb12u1
1:10.11.18-0+deb12u1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
2
yzhou442/equiz:latesta3f7ca69e28d
mysql-client@10.6.11-1
10.6.25
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
mariadb-10.1@1:10.1.47-0ubuntu0.18.04.1
no fix listed
2
apache/airflow:2.8.4-python3.964e58748b6b9
mariadb@1:10.11.7+maria~deb12
1:10.11.18-0+deb12u1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
mariadb@1:10.11.9+maria~deb12
1:10.11.18-0+deb12u1
1
apache/airflow:2.8.1e5560ad0b86e
mariadb@1:10.11.7+maria~deb12
1:10.11.18-0+deb12u1
1
apache/superset:4.0.1ab9467fd712c
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
mariadb@1:10.11.3-1
1:10.11.18-0+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
mariadb@1:10.11.3-1
1:10.11.18-0+deb12u1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
mariadb@1:10.11.11-0+deb12u1
1:10.11.18-0+deb12u1
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
mysql-client@10.11.10-0
10.6.25
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
mariadb@10.6.12-2
10.6.25
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
mariadb@11.3.2-5
MariaDB@11.3.2-5
10.6.25
10.6.25
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
mariadb@11.2.6-0
10.6.25
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
mariadb@10.6.12-3
10.6.25
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
mariadb@11.4.3-0
10.6.25
1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
mariadb@11.4.5-2
10.6.25
1
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
mariadb@11.4.7-0
10.6.25
1
bitnamilegacy/mariadb:latestbbd4e17f1ef8
mariadb@11.8.2-0
10.6.25
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
mysql-client@12.0.2-0
10.6.25
1
bitnami/mariadb:11.7.216a7dae804fb
mariadb@11.7.2-0
10.6.25
1
bnjbvr/kresus:0.22.137e216b182c8
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
boky/postfix:5.1.0aafc77238423
mariadb@1:11.8.3-0+deb13u1
1:11.8.6-0+deb13u1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
mariadb@1:11.8.3-0+deb13u1
1:11.8.6-0+deb13u1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
mariadb@1:10.11.11-0+deb12u1
1:10.11.18-0+deb12u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
mariadb@1:10.11.3-1
1:10.11.18-0+deb12u1
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
mariadb@1:10.11.4-1~deb12u1
1:10.11.18-0+deb12u1
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
jordan/icinga2:latestf75025fe8ea8
mariadb@1:10.11.14-0+deb12u2
1:10.11.18-0+deb12u1
1
knspar/phronetis-operator:0.1.60c4f0543ee58
mariadb@1:10.11.6-0+deb12u1
1:10.11.18-0+deb12u1
1
laly9999/node-app:1dd0e503913e1
mariadb@1:10.11.11-0+deb12u1
1:10.11.18-0+deb12u1
1
leantime/leantime:3.3.3ad4bfb0699d3
mariadb@10.11.10-r0
10.11.16-r0
1
library/mariadb:112439dcd7d140
mariadb@1:11.8.9+maria~ubu2404
no fix listed
1
library/mariadb:12.0.25b6a1eac15b8
mariadb@1:12.0.2+maria~ubu2404
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.