{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-3494",
        "tracking": {
            "current_release_date": "2026-03-23T04:22:25.513518Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-3494",
            "initial_release_date": "2026-03-03T18:38:41.108892Z",
            "revision_history": [
                {
                    "date": "2026-03-03T18:38:41.108892Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (15).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T18:38:47.370430Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-03T19:39:17.509263Z",
                    "number": "3",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-03T20:28:39.552545Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T20:28:44.816722Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T23:38:50.436822Z",
                    "number": "6",
                    "summary": "Products created (4).| Products removed (4)."
                },
                {
                    "date": "2026-03-04T12:46:00.861313Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (9).| Product Identifiers created (4).| Product Remediations created (9).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-04T12:46:03.340509Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T13:25:36.570075Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Products created (4).| References created (5)."
                },
                {
                    "date": "2026-03-04T13:25:39.022687Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:15:02.333594Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-09T18:25:48.255358Z",
                    "number": "12",
                    "summary": "Products created (15).| Product Identifiers created (15)."
                },
                {
                    "date": "2026-03-09T18:25:50.259362Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-10T12:05:42.421336Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (4).| References created (2)."
                },
                {
                    "date": "2026-03-10T12:05:43.023707Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (4).| References created (2)."
                },
                {
                    "date": "2026-03-10T12:05:43.931125Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (2)."
                },
                {
                    "date": "2026-03-10T12:05:53.816228Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-10T12:19:44.307050Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T12:19:46.199558Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-10T18:22:04.313033Z",
                    "number": "20",
                    "summary": "Products connected (1).| Product Remediations created (1)."
                },
                {
                    "date": "2026-03-10T18:22:07.134425Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-10T18:36:14.348240Z",
                    "number": "22",
                    "summary": "Source connected.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-03-10T18:36:16.551741Z",
                    "number": "23",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T10:23:56.037249Z",
                    "number": "24",
                    "summary": "Products connected (1).| Product Identifiers created (1).| References created (1)."
                },
                {
                    "date": "2026-03-14T00:21:44.187291Z",
                    "number": "25",
                    "summary": "Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-14T00:21:45.669768Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-14T12:20:04.170612Z",
                    "number": "27",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-03-16T17:39:16.847533Z",
                    "number": "28",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-16T17:39:21.610794Z",
                    "number": "29",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-16T18:26:37.066147Z",
                    "number": "30",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-16T18:26:43.671854Z",
                    "number": "31",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T00:19:54.520345Z",
                    "number": "32",
                    "summary": "Product Remediations removed (1)."
                },
                {
                    "date": "2026-03-17T12:05:38.495448Z",
                    "number": "33",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-17T12:19:52.284680Z",
                    "number": "34",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-03-20T09:28:45.946043Z",
                    "number": "35",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:28:50.107275Z",
                    "number": "36",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "36"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.12.6",
                                "product": {
                                    "name": "vers:unknown/2.12.6",
                                    "product_id": "CSAFPID-5757071"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.04.6",
                                "product": {
                                    "name": "vers:unknown/3.04.6",
                                    "product_id": "CSAFPID-5757072"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.10.3",
                                "product": {
                                    "name": "vers:unknown/3.10.3",
                                    "product_id": "CSAFPID-5757073"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.11.1",
                                "product": {
                                    "name": "vers:unknown/3.11.1",
                                    "product_id": "CSAFPID-5757074"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Aurora MySQL"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.11.16",
                                "product": {
                                    "name": "vers:unknown/10.11.16",
                                    "product_id": "CSAFPID-5757079"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.6.25",
                                "product": {
                                    "name": "vers:unknown/10.6.25",
                                    "product_id": "CSAFPID-5757078"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.4.10",
                                "product": {
                                    "name": "vers:unknown/11.4.10",
                                    "product_id": "CSAFPID-5757080"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.8.6",
                                "product": {
                                    "name": "vers:unknown/11.8.6",
                                    "product_id": "CSAFPID-5757081"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "RDS for MariaDB"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.7.44-rds.20260212",
                                "product": {
                                    "name": "vers:unknown/5.7.44-rds.20260212",
                                    "product_id": "CSAFPID-5757075"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.45",
                                "product": {
                                    "name": "vers:unknown/8.0.45",
                                    "product_id": "CSAFPID-5757076"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.4.8",
                                "product": {
                                    "name": "vers:unknown/8.4.8",
                                    "product_id": "CSAFPID-5757077"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "RDS for MySQL"
                    }
                ],
                "category": "vendor",
                "name": "Amazon"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/azl3",
                                "product": {
                                    "name": "vers:unknown/azl3",
                                    "product_id": "CSAFPID-5247946",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:microsoft:azure_linux:azl3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Azure Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5826716",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:azl3_mariadb_10.11.15-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "azl3 mariadb 10.11.15-1 on Azure Linux 3.0"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5775806",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:cbl2_mariadb_10.6.24-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Open Source Software"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<10.11.16",
                                "product": {
                                    "name": "vers:unknown/<10.11.16",
                                    "product_id": "CSAFPID-5758068"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<10.6.25",
                                "product": {
                                    "name": "vers:unknown/<10.6.25",
                                    "product_id": "CSAFPID-5758067"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<11.4.10",
                                "product": {
                                    "name": "vers:unknown/<11.4.10",
                                    "product_id": "CSAFPID-5758065"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<11.8.6",
                                "product": {
                                    "name": "vers:unknown/<11.8.6",
                                    "product_id": "CSAFPID-5758066"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "MariaDB"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=10.6.24",
                                "product": {
                                    "name": "vers:unknown/<=10.6.24",
                                    "product_id": "CSAFPID-5771974",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.7.0|<=10.11.15",
                                "product": {
                                    "name": "vers:unknown/>=10.7.0|<=10.11.15",
                                    "product_id": "CSAFPID-5771975",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.0.0|<=11.4.9",
                                "product": {
                                    "name": "vers:unknown/>=11.0.0|<=11.4.9",
                                    "product_id": "CSAFPID-5771976",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.5.0|<=11.8.5",
                                "product": {
                                    "name": "vers:unknown/>=11.5.0|<=11.8.5",
                                    "product_id": "CSAFPID-5771977",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "mariadb"
                    }
                ],
                "category": "vendor",
                "name": "MariaDB"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.11.16",
                                "product": {
                                    "name": "vers:unknown/10.11.16",
                                    "product_id": "CSAFPID-5757217"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.6.25",
                                "product": {
                                    "name": "vers:unknown/10.6.25",
                                    "product_id": "CSAFPID-5757216"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.4.10",
                                "product": {
                                    "name": "vers:unknown/11.4.10",
                                    "product_id": "CSAFPID-5757218"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.8.6",
                                "product": {
                                    "name": "vers:unknown/11.8.6",
                                    "product_id": "CSAFPID-5757219"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "MariaDB Server"
                    }
                ],
                "category": "vendor",
                "name": "MariaDB Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2452923"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mariadb"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2452924"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mariadb"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2452925"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mariadb"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5213595"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mariadb10.11"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5213596"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mariadb11.8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.11.0",
                                "product": {
                                    "name": "vers:unknown/3.11.0",
                                    "product_id": "CSAFPID-5771981",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:aurora_mysql:3.11.0:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.12.5",
                                "product": {
                                    "name": "vers:unknown/<=2.12.5",
                                    "product_id": "CSAFPID-5771978",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.01.0|<=3.04.5",
                                "product": {
                                    "name": "vers:unknown/>=3.01.0|<=3.04.5",
                                    "product_id": "CSAFPID-5771979",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.05.1|<=3.10.2",
                                "product": {
                                    "name": "vers:unknown/>=3.05.1|<=3.10.2",
                                    "product_id": "CSAFPID-5771980",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:aurora_mysql:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "aurora_mysql"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=10.6.24",
                                "product": {
                                    "name": "vers:unknown/<=10.6.24",
                                    "product_id": "CSAFPID-5771983",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=5.7.44-rds.20251212",
                                "product": {
                                    "name": "vers:unknown/<=5.7.44-rds.20251212",
                                    "product_id": "CSAFPID-5771982",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.11.4|<=10.11.15",
                                "product": {
                                    "name": "vers:unknown/>=10.11.4|<=10.11.15",
                                    "product_id": "CSAFPID-5771986",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.4.3|<=11.4.9",
                                "product": {
                                    "name": "vers:unknown/>=11.4.3|<=11.4.9",
                                    "product_id": "CSAFPID-5771987",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.8.3|<=11.8.5",
                                "product": {
                                    "name": "vers:unknown/>=11.8.3|<=11.8.5",
                                    "product_id": "CSAFPID-5771988",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mariadb:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=8.0.11|<=8.0.44",
                                "product": {
                                    "name": "vers:unknown/>=8.0.11|<=8.0.44",
                                    "product_id": "CSAFPID-5771984",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=8.4.3|<=8.4.7",
                                "product": {
                                    "name": "vers:unknown/>=8.4.3|<=8.4.7",
                                    "product_id": "CSAFPID-5771985",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:amazon:relational_database_service:*:*:*:*:*:mysql:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "relational_database_service"
                    }
                ],
                "category": "vendor",
                "name": "amazon"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<10.6.25",
                                "product": {
                                    "name": "vers:unknown/>=0|<10.6.25",
                                    "product_id": "CSAFPID-5774474"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.7.0|<10.11.16",
                                "product": {
                                    "name": "vers:unknown/>=10.7.0|<10.11.16",
                                    "product_id": "CSAFPID-5774475"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.0.0|<11.4.10",
                                "product": {
                                    "name": "vers:unknown/>=11.0.0|<11.4.10",
                                    "product_id": "CSAFPID-5774476"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.5.0|<11.8.6",
                                "product": {
                                    "name": "vers:unknown/>=11.5.0|<11.8.6",
                                    "product_id": "CSAFPID-5774477"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "mariadb"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<10.6.25",
                                "product": {
                                    "name": "vers:unknown/>=0|<10.6.25",
                                    "product_id": "CSAFPID-5774478"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.7.0|<10.11.16",
                                "product": {
                                    "name": "vers:unknown/>=10.7.0|<10.11.16",
                                    "product_id": "CSAFPID-5774479"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.0.0|<11.4.10",
                                "product": {
                                    "name": "vers:unknown/>=11.0.0|<11.4.10",
                                    "product_id": "CSAFPID-5774480"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.5.0|<11.8.6",
                                "product": {
                                    "name": "vers:unknown/>=11.5.0|<11.8.6",
                                    "product_id": "CSAFPID-5774481"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "mariadb-min"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<10.6.25",
                                "product": {
                                    "name": "vers:unknown/>=0|<10.6.25",
                                    "product_id": "CSAFPID-5774482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.7.0|<12.0.2",
                                "product": {
                                    "name": "vers:unknown/>=10.7.0|<12.0.2",
                                    "product_id": "CSAFPID-5774483"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "mysql-client"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-3494",
            "cwe": {
                "id": "CWE-778",
                "name": "Insufficient Logging"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-3494"
                },
                {
                    "category": "description",
                    "text": "In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-3494"
                },
                {
                    "category": "description",
                    "text": "No description is available for this CVE.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-3494"
                },
                {
                    "category": "description",
                    "text": "In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mariadb-2026-3494.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mariadb-min-2026-3494.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mysql-client-2026-3494.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "MariaDB Server Audit Plugin Comment Handling Bypass",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "other",
                    "text": "0.00013",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "5.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "5.4",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "VENDOR FIX as product remediation category, There is product data available from source Certbundde, There is product data available from source Nvd, There is news data available from source Bleepingcomputer",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is product_remediation data available from source Redhat, The value of the most recent CVSS (V3) score",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1439315",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-2452923",
                    "CSAFPID-2452924",
                    "CSAFPID-2452925",
                    "CSAFPID-2858634",
                    "CSAFPID-5213595",
                    "CSAFPID-5213596",
                    "CSAFPID-5758065",
                    "CSAFPID-5758066",
                    "CSAFPID-5758067",
                    "CSAFPID-5758068",
                    "CSAFPID-5771974",
                    "CSAFPID-5771975",
                    "CSAFPID-5771976",
                    "CSAFPID-5771977",
                    "CSAFPID-5771978",
                    "CSAFPID-5771979",
                    "CSAFPID-5771980",
                    "CSAFPID-5771981",
                    "CSAFPID-5771982",
                    "CSAFPID-5771983",
                    "CSAFPID-5771984",
                    "CSAFPID-5771985",
                    "CSAFPID-5771986",
                    "CSAFPID-5771987",
                    "CSAFPID-5771988",
                    "CSAFPID-5774474",
                    "CSAFPID-5774475",
                    "CSAFPID-5774476",
                    "CSAFPID-5774477",
                    "CSAFPID-5774478",
                    "CSAFPID-5774479",
                    "CSAFPID-5774480",
                    "CSAFPID-5774481",
                    "CSAFPID-5774482",
                    "CSAFPID-5774483",
                    "CSAFPID-5775806",
                    "CSAFPID-5247946",
                    "CSAFPID-5826716"
                ],
                "known_not_affected": [
                    "CSAFPID-5757071",
                    "CSAFPID-5757072",
                    "CSAFPID-5757073",
                    "CSAFPID-5757074",
                    "CSAFPID-5757075",
                    "CSAFPID-5757076",
                    "CSAFPID-5757077",
                    "CSAFPID-5757078",
                    "CSAFPID-5757079",
                    "CSAFPID-5757080",
                    "CSAFPID-5757081",
                    "CSAFPID-5757216",
                    "CSAFPID-5757217",
                    "CSAFPID-5757218",
                    "CSAFPID-5757219"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/3xxx/CVE-2026-3494.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-3494.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0585.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mariadb-2026-3494.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mariadb-min-2026-3494.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-mysql-client-2026-3494.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "external",
                    "summary": "Source - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "News - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv; redhat",
                    "url": "https://aws.amazon.com/security/security-bulletins/2026-006-AWS/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3494"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0585.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0585"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-qmjm-438j-w485"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://mariadb.com/docs/release-notes/latest-releases"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://aws.amazon.com/de/security/security-bulletins/2026-006-AWS/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://msrc.microsoft.com/update-guide/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/MariaDB/server/commit/635559a2ad68a5a6d1a354e8209c58323dba0261"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/aws/audit-plugin-for-mysql/commit/01e25a5cb1073f131eea774c06c8a056b1e4b2ff"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "To prevent authenticated users from bypassing logging of SQL statements prefixed with comments, disable the MariaDB Server Audit Plugin if its current behavior is not suitable for your auditing requirements.\nTo disable the plugin, modify your MariaDB configuration file (e.g., `/etc/my.cnf` or a file in `/etc/my.cnf.d/`) to set `server_audit_logging=OFF` within the `[mariadb]` section.\n```\n[mariadb]\nserver_audit_logging=OFF\n```\nAfter modifying the configuration, restart the MariaDB service for the changes to take effect:\n```bash\nsystemctl restart mariadb\n```\nDisabling this plugin will cease all auditing performed by the MariaDB Server Audit Plugin. Ensure this aligns with your security policies and that alternative auditing mechanisms are in place if comprehensive logging is required.",
                    "product_ids": [
                        "CSAFPID-1439315",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-2452923",
                        "CSAFPID-2452924",
                        "CSAFPID-2452925",
                        "CSAFPID-2858634",
                        "CSAFPID-5213595",
                        "CSAFPID-5213596"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "CBL-Mariner Releases",
                    "product_ids": [
                        "CSAFPID-5775806",
                        "CSAFPID-5826716"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1439315",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-2452923",
                        "CSAFPID-2452924",
                        "CSAFPID-2452925",
                        "CSAFPID-2858634",
                        "CSAFPID-5213595",
                        "CSAFPID-5213596",
                        "CSAFPID-5247946",
                        "CSAFPID-5758065",
                        "CSAFPID-5758066",
                        "CSAFPID-5758067",
                        "CSAFPID-5758068",
                        "CSAFPID-5771974",
                        "CSAFPID-5771975",
                        "CSAFPID-5771976",
                        "CSAFPID-5771977",
                        "CSAFPID-5771978",
                        "CSAFPID-5771979",
                        "CSAFPID-5771980",
                        "CSAFPID-5771981",
                        "CSAFPID-5771982",
                        "CSAFPID-5771983",
                        "CSAFPID-5771984",
                        "CSAFPID-5771985",
                        "CSAFPID-5771986",
                        "CSAFPID-5771987",
                        "CSAFPID-5771988",
                        "CSAFPID-5774474",
                        "CSAFPID-5774475",
                        "CSAFPID-5774476",
                        "CSAFPID-5774477",
                        "CSAFPID-5774478",
                        "CSAFPID-5774479",
                        "CSAFPID-5774480",
                        "CSAFPID-5774481",
                        "CSAFPID-5774482",
                        "CSAFPID-5774483",
                        "CSAFPID-5775806",
                        "CSAFPID-5826716"
                    ]
                }
            ],
            "title": "CVE-2026-3494"
        }
    ]
}