Root cause
JSON normalization copied variable-length text into an undersized allocation. The fix uses storage management that grows the buffer to fit the value.
Demonstrated impact
An authenticated database user could crash the server. The researcher demonstrated code execution at the event; the vendor-authored CVE record qualifies that outcome as dependent on unusually controlled memory conditions, generally associated with a lab.
Lessons for review
- Make input length and allocated capacity explicit invariants in normalization code.
- Prefer capacity-aware storage operations and safe local regression coverage.
- Separate a controlled demonstration from deployment-wide impact claims.
Award and evidence
One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made.
Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.
- Vendor CVE wording conditions code execution on tight memory control generally obtainable in a lab; do not infer reliable production-wide compromise.
- Vendor advisory also lists patched 12.2.2, beyond the two release series emphasized in the research article. The February 4 fix date refers to the reviewed 11.4.10 release.
- The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.
- Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.
- Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules.
Recorded timeline
- Published
- 2026-05-04inferred · Displayed May 4; year inferred from the completed 2026 remediation timeline.
- Public Disclosure
- 2025-12-11explicit · Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events.
- Reported
- 2025-12-11explicit · Researcher timeline explicitly dates the report and vendor acknowledgement.
- Fixed
- 2026-02-04explicit · Vendor patch release, not proof of deployment by every customer.
- Award Announced
- 2025-12-16explicit · Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown.
Sources and provenance
- CVE-2026-32710: MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE Team Xint Code / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
- ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
- MariaDB heap-based buffer overflow in JSON_SCHEMA_VALID MariaDB · reviewed 2026-10-02
- CVE-2026-32710 CNA record GitHub CNA, MariaDB advisory / CVE Program · reviewed 2026-10-02
- MariaDB 11.4.10 release notes MariaDB · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.