> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/release-notes/connectors/java/2.7/2.7.15.md).

# Connector/J 2.7.15 Release Notes

{% hint style="info" %}

<p align="center">The most recent release of <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/Y7PAVcAiFWL6chXpLkk5">MariaDB Connector/J</a> is: <a href="/pages/8eywym9CP3JwsmgctOpj"><strong>3.5.10</strong></a></p>

<p align="center"><a href="https://mariadb.com/downloads/connectors/connectors-data-access/java8-connector" class="button primary">Download Connector/J 3.5.10</a></p>
{% endhint %}

<a href="https://mariadb.com/downloads/connectors/connectors-data-access/java8-connector" class="button primary">Download</a> <a href="/pages/rFJaqIBKoCS13MOLn8L9" class="button secondary">Release Notes</a> <a href="/pages/TfejqgBGQ9doOdHmjnh7" class="button secondary">Changelog</a> <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/2w3wOBJquBYSZu4GiT0h" class="button secondary">Connector/J Overview</a>

**Release date:** 29 Jul 2026

MariaDB Connector/J 2.7.15 is a [***Stable***](/docs/release-notes/community-server/about/release-criteria.md) ***(GA)*** release.

{% hint style="info" %}
**For an overview of MariaDB Connector/J see the** [**About MariaDB Connector/J**](/docs/connectors/mariadb-connector-j/about-mariadb-connector-j.md) **page**
{% endhint %}

## Notable Changes

* [CONJ-1339](https://jira.mariadb.org/browse/CONJ-1339) - Add the `maxAllowedColumns` connection option, bounding the server-announced column count (report by fg0x0)

## Bugs Fixed

* [CONJ-1342](https://jira.mariadb.org/browse/CONJ-1342) - The `socketFactory` option allows loading arbitrary bytecode through a `jar:` URL, enabling remote code execution when the JDBC URL is attacker-controlled (report by Qing Xu)
* [CONJ-1332](https://jira.mariadb.org/browse/CONJ-1332) - Reject multipart (larger than 16MB) packets before authentication, to prevent a pre-authentication out-of-memory condition caused by a rogue server
* [CONJ-1340](https://jira.mariadb.org/browse/CONJ-1340) - SQL injection through unescaped identifiers in the statements generated for an updatable `ResultSet` (thanks to jmestwa-coder)
* [CONJ-1326](https://jira.mariadb.org/browse/CONJ-1326) - Unsafe escaping in `enquoteLiteral()` and `enquoteNCharLiteral()` (thanks to jmestwa-coder)

#### Other

* Cap the length-encoded field length before narrowing it to an `int` in the row decoders

## Changelog

For a complete list of changes made in MariaDB Connector/J 2.7.15, with links to detailed\
information on each push, see the [changelog](/docs/release-notes/connectors/java/changelogs/2.7/2.7.15.md).

<sub>*This page is: Copyright © 2025 MariaDB. All rights reserved.*</sub>

{% @marketo/form formid="4316" formId="4316" %}
