github source

github.advisories

pass

List global security advisories

Works without WHERE filters. Most useful optional filters: type, sort, ghsa_id. Add ghsa_id to jump from the default list call to a specific record lookup.

no filters captured 2026-08-31 05:26:43Zmedian 27396 ms
Verdict: TRUE

All variants returned rows on ≥2 trials, 0 errors.

rendering…

Summary

VariantTrialsMinMedianMaxRow countsErrors
minimal230137 ms30479 ms30822 ms[26, 26]0
realistic225721 ms27396 ms29072 ms[200, 200]0
edge222410 ms26567 ms30725 ms[200, 200]0

Latency per trial

minimalmedian 30479ms
t130822mst230137ms
scale: 0–30822 ms
realisticmedian 27396ms
t129072mst225721ms
scale: 0–29072 ms
edgemedian 26567ms
t130725mst222410ms
scale: 0–30725 ms

Probe variants — every command + output

minimal2 trials
min 30137ms · median 30479ms · max 30822ms · rows 26,26

smallest valid query (no filters)

Command
SELECT * FROM github.advisories LIMIT 1
Trials + output
trial 1·30822ms·rows 26isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·30137ms·rows 26isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
realistic2 trials
min 25721ms · median 27396ms · max 29072ms · rows 200,200

typical user query (no filters)

Command
SELECT * FROM github.advisories LIMIT 25
Trials + output
trial 1·29072ms·rows 200isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·25721ms·rows 200isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
edge2 trials
min 22410ms · median 26567ms · max 30725ms · rows 200,200

edge: larger limit, no filters

Command
SELECT * FROM github.advisories LIMIT 200
Trials + output
trial 1·30725ms·rows 200isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·22410ms·rows 200isError=false
First row (click to expand JSON)
{
  "affects": "",
  "credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
  "cve_id": "CVE-2026-55855",
  "cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
  "cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
  "cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
  "description": "### Summary",
  "direction": "",
  "ecosystem": "",
  "epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
  "epss_percentage": "",
  "epss_percentile": "",
  "ghsa_id": "GHSA-g5xc-5w98-jfvm",
  "github_reviewed_at": "2026-08-28T22:53:12Z",
  "html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
  "is_withdrawn": "",
  "modified": "",
  "nvd_published_at": "",
  "published": "",
  "published_at": "2026-08-28T22:53:12Z",
  "references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
  "repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
  "severity": "medium",
  "sort": "",
  "source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
  "summary": "MariaDB has  possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
  "type": "reviewed",
  "updated": "",
  "updated_at": "2026-08-28T22:53:13Z",
  "url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
  "vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
  "withdrawn_at": ""
}
columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at

All returned rowsacross all non-errored trials · filterable · paginated

852 rows stored · 852 returned · page 1/35
10[{"user":{"login":"fg0x0","id":35772301,"node_id":"MDQ6VXNlcjM1NzcyMzAx","avata…CVE-2026-55855{"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","score":6.5}{"cvss_v3":{"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","sco…[{"cwe_id":"CWE-89","name":"Improper Neutralization of Special Elements used in…### Summary{"percentage":0.00311,"percentile":0.23301}GHSA-g5xc-5w98-jfvm2026-08-28T22:53:12Zhttps://github.com/advisories/GHSA-g5xc-5w98-jfvm[{"value":"GHSA-g5xc-5w98-jfvm","type":"GHSA"},{"value":"CVE-2026-55855","type"…2026-08-28T22:53:12Z["https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advi…https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/secur…mediumhttps://github.com/mariadb-corporation/mariadb-connector-nodejsMariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk…reviewed2026-08-28T22:53:13Zhttps://api.github.com/advisories/GHSA-g5xc-5w98-jfvm[{"package":{"ecosystem":"npm","name":"mariadb"},"vulnerable_version_range":"< …
11A SQL injection is possible when the connector escapes Buffer parameters client…
12### Details
13When binding a Buffer (binary) parameter, the connector escapes the value byte-…
14On the server, the SQL lexer performs multi-byte character recognition (my_ismb…
15This is the well-known multi-byte escaping bypass (the same class that historic…
16### Am I affected?
17You are affected if all of the following hold:
18You use mariadb Connector/Node.js at a version below the patched releases liste…
19The connection's client character set is one of big5, gbk, sjis, cp932, or gb18…
110Untrusted data can reach a Buffer-typed query parameter.
111Applications using utf8mb4 (or any charset whose trail-byte range does not incl…
112### Impact
113SQL injection. An attacker able to influence the contents of a Buffer parameter…
114### Patches
115Fixed in 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Upgrade to the patched release on your…
116* 3.5.x → 3.5.3
117* 3.4.x → 3.4.6
118* 3.3.x → 3.3.3
119* 3.2.x and earlier → 3.2.4 (or any newer release)
120### Workarounds
121If you cannot upgrade immediately:
122Use server-side prepared statements (execute) so parameters are bound via the b…
123Avoid passing untrusted data as Buffer parameters under the affected charsets.
124Credit

Column profile

33 columns actually returned by coral. Catalog claims no required filters. Click a column to drill in.

#ColumnInferred typeNon-nullNullsSample value(s)
1affects06empty
2creditsstring60"[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlc"
3cve_idstring60"CVE-2026-55855"
4cvssstring60"{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A"
5cvss_severitiesstring60"{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:"
6cwesstring60"[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Speci"
7descriptionstring60"### Summary"
8direction06empty
9ecosystem06empty
10epssstring60"{\"percentage\":0.00311,\"percentile\":0.23301}"
11epss_percentage06empty
12epss_percentile06empty
13ghsa_idstring60"GHSA-g5xc-5w98-jfvm"
14github_reviewed_atstring60"2026-08-28T22:53:12Z"
15html_urlstring60"https://github.com/advisories/GHSA-g5xc-5w98-jfvm"
16identifiersstring60"[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE"
17is_withdrawn06empty
18modified06empty
19nvd_published_at06empty
20published06empty
21published_atstring60"2026-08-28T22:53:12Z"
22referencesstring60"[\"https://github.com/mariadb-corporation/mariadb-connector-n"
23repository_advisory_urlstring60"https://api.github.com/repos/mariadb-corporation/mariadb-con"
24severitystring60"medium"
25sort06empty
26source_code_locationstring60"https://github.com/mariadb-corporation/mariadb-connector-nod"
27summarystring60"MariaDB has possible SQL injection in Buffer parameter esca"
28typestring60"reviewed"
29updated06empty
30updated_atstring60"2026-08-28T22:53:13Z"
31urlstring60"https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm"
32vulnerabilitiesstring60"[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable"
33withdrawn_at06empty

Trial comparison

Variant / comboTrial #LatencyRowsStatusFirst key returned
minimalt130822ms26okaffects, credits, cve_id
minimalt230137ms26okaffects, credits, cve_id
realistict129072ms200okaffects, credits, cve_id
realistict225721ms200okaffects, credits, cve_id
edget130725ms200okaffects, credits, cve_id
edget222410ms200okaffects, credits, cve_id

Catalog vs. response schemaclaimed guide vs columns coral actually returned

Catalog guide (verbatim)
Works without WHERE filters. Most useful optional filters: type, sort, ghsa_id. Add ghsa_id to jump from the default list call to a specific record lookup.
Columns coral returned (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
Probed by bld-dabqr1nqj5pc73dgn3h0-676t6 at 2026-08-31T05:26:43Z
JSON record: reports/github/tables/advisories.json
first_run_at: 2026-08-31T05:19:51Z
last_retried_at: 2026-08-31T05:26:43Z
retry_count: 1
View version history →