News

MariaDB: security reports surge in 2026, from a handful to 92 per quarter

MariaDB explains why some 2026 releases arrived late: security reports jumped from a few dozen to 81 and 92 per quarter, driven by AI-assisted tools.

UptimeMag editorial team · 2 October 2026 · 2 min read

MariaDB: boom di segnalazioni di sicurezza nel 2026, da pochi report a 92 a trimestre

On 2 October 2026, MariaDB published an explanation on its official blog for the delays some users have noticed in recent server releases: it's not a development problem, but an unprecedented increase in the security reports received by the project. For anyone running MariaDB instances in production, understanding where this workload is coming from helps gauge how much to trust the patches and what to expect from upcoming releases.

From a handful of reports to 92 in a single quarter

According to the chart shared by the project, for years MariaDB received only a few security reports per quarter: sometimes 3, sometimes 6, with a historic high of 16. During 2026 this number rose to 81 in one quarter and 92 in the next. MariaDB is careful to point out that 173 reports do not equate to 173 vulnerabilities: every report is investigated, reproduced and assessed, and only a fraction of them turn out to be confirmed vulnerabilities.

The project attributes the spike to security researchers' use of AI-assisted tools, which are able to analyse large codebases, trace code paths and spot suspicious patterns in areas that previously required a great deal of manual work. MariaDB stresses that the vast majority of reports received were genuine, not "AI slop" — plausible-sounding explanations with no actual bug behind them.

In-house advisories and fixes already shipped

To communicate confirmed vulnerabilities without waiting for a CVE to be assigned, MariaDB has started publishing its own MariaDB Security Advisories: at the time the post was published, 27 had been issued and fixed in the latest maintenance releases of the supported Community and Enterprise versions. The connectors also have their own dedicated advisories.

Among the researchers mentioned, fg0x0 submitted 51 reports focused on the MariaDB Connectors, including an issue in Connector/Node.js related to PAM authentication and credentials being sent over an insecure transport, which has already been fixed. On the server side, letchu_pkt (13 reports) flagged several issues in Galera/wsrep, including values passed to shell commands, fixed in the maintained releases; next come vortfu (12 reports, from Automattic) and muhammaddaffa (10 reports).

MariaDB is encouraging researchers to keep reporting issues through its private security channels, providing reproducible test cases where possible. Source: official MariaDB.org blog, "When AI Finds the Bugs We Missed: A Very Busy Year for MariaDB Security".

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: MariaDB – rilasci.