CVE-2026-49261 MariaDB server has unsafe parameter handling in
wsrep_notify_cmd
CVE-2026-48165 MariaDB: unsafe usage of wsrep_sst_receive_address
values on the joiner side
CVE-2026-48163 MariaDB: wsrep SST unsafe parameter handling on the donor
side (rsync)