StackRadar

CVE-2026-55215

High

Advisory

Published 28 Aug 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
mariadbnpm2.4.1, 2.5.1, 2.5.2, 2.5.3+5 more3.2.4, 3.4.69
OSV records
GHSA-cqhc-2h57-wpxf
Also known as
BIT-mariadb-2026-55215, BIT-mariadb-min-2026-55215, BIT-mysql-client-2026-55215

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
mariadb@2.5.1
3.2.4

Open the chart page →

2,851
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
mariadb@3.4.5
3.4.6

Open the chart page →

1,755
contentbridgeglenndehaanVerified publisher1.1.01 of 1See more

contentbridge glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
glenndehaan/contentbridge:latest99b9e4f73848
mariadb@3.2.0
3.2.4

Open the chart page →

1,000
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
mariadb@3.0.2
3.2.4

Open the chart page →

10,546
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
mariadb@2.5.3
3.2.4

Open the chart page →

3,397
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
mariadb@2.4.1
3.2.4

Open the chart page →

6,684
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
mariadb@2.5.2
3.2.4

Open the chart page →

27,465
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
mariadb@3.2.3
3.2.4

Open the chart page →

6,282
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
mariadb@3.0.0
3.2.4

Open the chart page →

3,118
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55215.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
mariadb@3.0.0
3.2.4

Open the chart page →

3,118

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
mariadb@3.0.0
3.2.4
2
glenndehaan/contentbridge:latest99b9e4f73848
mariadb@3.2.0
3.2.4
1
linuxserver/codimd:latestb801bbcf6386
mariadb@2.5.2
3.2.4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
mariadb@2.4.1
3.2.4
1
sqlpad/sqlpad:6.7d3d2f430dffd
mariadb@2.5.3
3.2.4
1
zooz/predator:1.6f491d1f7a865
mariadb@2.5.1
3.2.4
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
mariadb@3.0.2
3.2.4
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
mariadb@3.2.3
3.2.4
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
mariadb@3.4.5
3.4.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.