github source
pass
View version history →
github.advisories
passList global security advisories
Works without WHERE filters. Most useful optional filters: type, sort, ghsa_id. Add ghsa_id to jump from the default list call to a specific record lookup.
no filters captured 2026-08-31 05:26:43Zmedian 27396 ms
Verdict: TRUE
All variants returned rows on ≥2 trials, 0 errors.
rendering…
Summary
| Variant | Trials | Min | Median | Max | Row counts | Errors |
|---|---|---|---|---|---|---|
| minimal | 2 | 30137 ms | 30479 ms | 30822 ms | [26, 26] | 0 |
| realistic | 2 | 25721 ms | 27396 ms | 29072 ms | [200, 200] | 0 |
| edge | 2 | 22410 ms | 26567 ms | 30725 ms | [200, 200] | 0 |
Latency per trial
minimalmedian 30479ms
scale: 0–30822 ms
realisticmedian 27396ms
scale: 0–29072 ms
edgemedian 26567ms
scale: 0–30725 ms
Probe variants — every command + output
minimal
2 trialsmin 30137ms · median 30479ms · max 30822ms · rows 26,26
smallest valid query (no filters)
Command
SELECT * FROM github.advisories LIMIT 1Trials + output
trial 1·30822ms·rows 26isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·30137ms·rows 26isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
realistic
2 trialsmin 25721ms · median 27396ms · max 29072ms · rows 200,200
typical user query (no filters)
Command
SELECT * FROM github.advisories LIMIT 25Trials + output
trial 1·29072ms·rows 200isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·25721ms·rows 200isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
edge
2 trialsmin 22410ms · median 26567ms · max 30725ms · rows 200,200
edge: larger limit, no filters
Command
SELECT * FROM github.advisories LIMIT 200Trials + output
trial 1·30725ms·rows 200isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
trial 2·22410ms·rows 200isError=false
First row (click to expand JSON)
{
"affects": "",
"credits": "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlcjM1NzcyMzAx\",\"avatar_url\":\"https://avatars.githubusercontent.com/u/35772301?v=4\",\"gravatar_id\":\"\",\"url\":\"https://api.github.com/users/fg0x0\",\"html_url\":\"https://github.com/fg0x0\",\"followers_url\":\"https://api.github.com/users/fg0x0/followers\",\"following_url\":\"https://api.github.com/users/fg0x0/following{/other_user}\",\"gists_url\":\"https://api.github.com/users/fg0x0/gists{/gist_id}\",\"starred_url\":\"https://api.github.com/users/fg0x0/starred{/owner}{/repo}\",\"subscriptions_url\":\"https://api.github.com/users/fg0x0/subscriptions\",\"organizations_url\":\"https://api.github.com/users/fg0x0/orgs\",\"repos_url\":\"https://api.github.com/users/fg0x0/repos\",\"events_url\":\"https://api.github.com/users/fg0x0/events{/privacy}\",\"received_events_url\":\"https://api.github.com/users/fg0x0/received_events\",\"type\":\"User\",\"user_view_type\":\"public\",\"site_admin\":false},\"type\":\"reporter\"}]",
"cve_id": "CVE-2026-55855",
"cvss": "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5}",
"cvss_severities": "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N\",\"score\":6.5},\"cvss_v4\":{\"vector_string\":null,\"score\":0.0}}",
"cwes": "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\"},{\"cwe_id\":\"CWE-116\",\"name\":\"Improper Encoding or Escaping of Output\"}]",
"description": "### Summary",
"direction": "",
"ecosystem": "",
"epss": "{\"percentage\":0.00311,\"percentile\":0.23301}",
"epss_percentage": "",
"epss_percentile": "",
"ghsa_id": "GHSA-g5xc-5w98-jfvm",
"github_reviewed_at": "2026-08-28T22:53:12Z",
"html_url": "https://github.com/advisories/GHSA-g5xc-5w98-jfvm",
"identifiers": "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE-2026-55855\",\"type\":\"CVE\"}]",
"is_withdrawn": "",
"modified": "",
"nvd_published_at": "",
"published": "",
"published_at": "2026-08-28T22:53:12Z",
"references": "[\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-g5xc-5w98-jfvm\",\"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/0148cadba48064d430902678bbc5b4b62dc1c04f\",\"https://jira.mariadb.org/browse/CONJS-350\",\"https://github.com/advisories/GHSA-g5xc-5w98-jfvm\"]",
"repository_advisory_url": "https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/security-advisories/GHSA-g5xc-5w98-jfvm",
"severity": "medium",
"sort": "",
"source_code_location": "https://github.com/mariadb-corporation/mariadb-connector-nodejs",
"summary": "MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets",
"type": "reviewed",
"updated": "",
"updated_at": "2026-08-28T22:53:13Z",
"url": "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm",
"vulnerabilities": "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\"< 3.2.4\",\"first_patched_version\":\"3.2.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.3.0, < 3.3.3\",\"first_patched_version\":\"3.3.4\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.4.0, < 3.4.6\",\"first_patched_version\":\"3.4.6\",\"vulnerable_functions\":[]},{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable_version_range\":\">= 3.5.0, < 3.5.3\",\"first_patched_version\":\"3.5.3\",\"vulnerable_functions\":[]}]",
"withdrawn_at": ""
}columns (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
All returned rowsacross all non-errored trials · filterable · paginated
852 rows stored · 852 returned · page 1/35
| 1 | 0 | — | [{"user":{"login":"fg0x0","id":35772301,"node_id":"MDQ6VXNlcjM1NzcyMzAx","avata… | CVE-2026-55855 | {"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","score":6.5} | {"cvss_v3":{"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","sco… | [{"cwe_id":"CWE-89","name":"Improper Neutralization of Special Elements used in… | ### Summary | — | — | {"percentage":0.00311,"percentile":0.23301} | — | — | GHSA-g5xc-5w98-jfvm | 2026-08-28T22:53:12Z | https://github.com/advisories/GHSA-g5xc-5w98-jfvm | [{"value":"GHSA-g5xc-5w98-jfvm","type":"GHSA"},{"value":"CVE-2026-55855","type"… | — | — | — | — | 2026-08-28T22:53:12Z | ["https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advi… | https://api.github.com/repos/mariadb-corporation/mariadb-connector-nodejs/secur… | medium | — | https://github.com/mariadb-corporation/mariadb-connector-nodejs | MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk… | reviewed | — | 2026-08-28T22:53:13Z | https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm | [{"package":{"ecosystem":"npm","name":"mariadb"},"vulnerable_version_range":"< … | — |
| 1 | 1 | — | — | — | — | — | — | A SQL injection is possible when the connector escapes Buffer parameters client… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 2 | — | — | — | — | — | — | ### Details | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 3 | — | — | — | — | — | — | When binding a Buffer (binary) parameter, the connector escapes the value byte-… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 4 | — | — | — | — | — | — | On the server, the SQL lexer performs multi-byte character recognition (my_ismb… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 5 | — | — | — | — | — | — | This is the well-known multi-byte escaping bypass (the same class that historic… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 6 | — | — | — | — | — | — | ### Am I affected? | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 7 | — | — | — | — | — | — | You are affected if all of the following hold: | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 8 | — | — | — | — | — | — | You use mariadb Connector/Node.js at a version below the patched releases liste… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 9 | — | — | — | — | — | — | The connection's client character set is one of big5, gbk, sjis, cp932, or gb18… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 10 | — | — | — | — | — | — | Untrusted data can reach a Buffer-typed query parameter. | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 11 | — | — | — | — | — | — | Applications using utf8mb4 (or any charset whose trail-byte range does not incl… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 12 | — | — | — | — | — | — | ### Impact | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 13 | — | — | — | — | — | — | SQL injection. An attacker able to influence the contents of a Buffer parameter… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 14 | — | — | — | — | — | — | ### Patches | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 15 | — | — | — | — | — | — | Fixed in 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Upgrade to the patched release on your… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 16 | — | — | — | — | — | — | * 3.5.x → 3.5.3 | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 17 | — | — | — | — | — | — | * 3.4.x → 3.4.6 | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 18 | — | — | — | — | — | — | * 3.3.x → 3.3.3 | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 19 | — | — | — | — | — | — | * 3.2.x and earlier → 3.2.4 (or any newer release) | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 20 | — | — | — | — | — | — | ### Workarounds | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 21 | — | — | — | — | — | — | If you cannot upgrade immediately: | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 22 | — | — | — | — | — | — | Use server-side prepared statements (execute) so parameters are bound via the b… | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 23 | — | — | — | — | — | — | Avoid passing untrusted data as Buffer parameters under the affected charsets. | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
| 1 | 24 | — | — | — | — | — | — | Credit | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — | — |
Column profile
33 columns actually returned by coral. Catalog claims no required filters. Click a column to drill in.
| # | Column | Inferred type | Non-null | Nulls | Sample value(s) |
|---|---|---|---|---|---|
| 1 | affects | — | 0 | 6 | empty |
| 2 | credits | string | 6 | 0 | "[{\"user\":{\"login\":\"fg0x0\",\"id\":35772301,\"node_id\":\"MDQ6VXNlc" |
| 3 | cve_id | string | 6 | 0 | "CVE-2026-55855" |
| 4 | cvss | string | 6 | 0 | "{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A" |
| 5 | cvss_severities | string | 6 | 0 | "{\"cvss_v3\":{\"vector_string\":\"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:" |
| 6 | cwes | string | 6 | 0 | "[{\"cwe_id\":\"CWE-89\",\"name\":\"Improper Neutralization of Speci" |
| 7 | description | string | 6 | 0 | "### Summary" |
| 8 | direction | — | 0 | 6 | empty |
| 9 | ecosystem | — | 0 | 6 | empty |
| 10 | epss | string | 6 | 0 | "{\"percentage\":0.00311,\"percentile\":0.23301}" |
| 11 | epss_percentage | — | 0 | 6 | empty |
| 12 | epss_percentile | — | 0 | 6 | empty |
| 13 | ghsa_id | string | 6 | 0 | "GHSA-g5xc-5w98-jfvm" |
| 14 | github_reviewed_at | string | 6 | 0 | "2026-08-28T22:53:12Z" |
| 15 | html_url | string | 6 | 0 | "https://github.com/advisories/GHSA-g5xc-5w98-jfvm" |
| 16 | identifiers | string | 6 | 0 | "[{\"value\":\"GHSA-g5xc-5w98-jfvm\",\"type\":\"GHSA\"},{\"value\":\"CVE" |
| 17 | is_withdrawn | — | 0 | 6 | empty |
| 18 | modified | — | 0 | 6 | empty |
| 19 | nvd_published_at | — | 0 | 6 | empty |
| 20 | published | — | 0 | 6 | empty |
| 21 | published_at | string | 6 | 0 | "2026-08-28T22:53:12Z" |
| 22 | references | string | 6 | 0 | "[\"https://github.com/mariadb-corporation/mariadb-connector-n" |
| 23 | repository_advisory_url | string | 6 | 0 | "https://api.github.com/repos/mariadb-corporation/mariadb-con" |
| 24 | severity | string | 6 | 0 | "medium" |
| 25 | sort | — | 0 | 6 | empty |
| 26 | source_code_location | string | 6 | 0 | "https://github.com/mariadb-corporation/mariadb-connector-nod" |
| 27 | summary | string | 6 | 0 | "MariaDB has possible SQL injection in Buffer parameter esca" |
| 28 | type | string | 6 | 0 | "reviewed" |
| 29 | updated | — | 0 | 6 | empty |
| 30 | updated_at | string | 6 | 0 | "2026-08-28T22:53:13Z" |
| 31 | url | string | 6 | 0 | "https://api.github.com/advisories/GHSA-g5xc-5w98-jfvm" |
| 32 | vulnerabilities | string | 6 | 0 | "[{\"package\":{\"ecosystem\":\"npm\",\"name\":\"mariadb\"},\"vulnerable" |
| 33 | withdrawn_at | — | 0 | 6 | empty |
Trial comparison
| Variant / combo | Trial # | Latency | Rows | Status | First key returned |
|---|---|---|---|---|---|
| minimal | t1 | 30822ms | 26 | ok | affects, credits, cve_id |
| minimal | t2 | 30137ms | 26 | ok | affects, credits, cve_id |
| realistic | t1 | 29072ms | 200 | ok | affects, credits, cve_id |
| realistic | t2 | 25721ms | 200 | ok | affects, credits, cve_id |
| edge | t1 | 30725ms | 200 | ok | affects, credits, cve_id |
| edge | t2 | 22410ms | 200 | ok | affects, credits, cve_id |
Catalog vs. response schemaclaimed guide vs columns coral actually returned
Catalog guide (verbatim)
Works without WHERE filters. Most useful optional filters: type, sort, ghsa_id. Add ghsa_id to jump from the default list call to a specific record lookup.Columns coral returned (33)
affectscreditscve_idcvsscvss_severitiescwesdescriptiondirectionecosystemepssepss_percentageepss_percentileghsa_idgithub_reviewed_athtml_urlidentifiersis_withdrawnmodifiednvd_published_atpublishedpublished_atreferencesrepository_advisory_urlseveritysortsource_code_locationsummarytypeupdatedupdated_aturlvulnerabilitieswithdrawn_at
Probed by
bld-dabqr1nqj5pc73dgn3h0-676t6 at 2026-08-31T05:26:43ZJSON record:
reports/github/tables/advisories.jsonfirst_run_at:
2026-08-31T05:19:51Zlast_retried_at:
2026-08-31T05:26:43Zretry_count:
1