> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/release-notes/connectors/node.js/3.x/3.3.3.md).

# Connector/Node.js 3.3.3 Release Notes

{% hint style="info" %}

<p align="center">The most recent release of <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/WmpaptiE3kKy2mNO6ps0">MariaDB Connector/Node.js</a> is: <a href="/pages/r2pMUZbAXRLBlqvRUjpX"><strong>3.5.3</strong></a></p>

<p align="center"><a href="https://mariadb.com/downloads/connectors/connectors-data-access/nodejs-connector" class="button primary">Download Connector/Node.js 3.5.3</a></p>
{% endhint %}

<a href="https://mariadb.com/downloads/connectors/connectors-data-access/nodejs-connector" class="button primary">Download</a> <a href="/pages/TVu4m4wxWCyrx8cvaECg" class="button secondary">Release Notes</a> <a href="/pages/RrgQXX5dce8HJ6f9EIyp" class="button secondary">Changelog</a> <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/x5uWNz6Wb26ooKT9S74U" class="button secondary">Connector/Node.js Overview</a>

**Release date:** 9 Jun 2026

MariaDB Connector/Node.js 3.3.3 is a [***Stable***](/docs/release-notes/community-server/about/release-criteria.md) ***(GA)*** release.

{% hint style="success" %}
**For an overview of MariaDB Connector/Node.js see the** [**About MariaDB Connector/Node.js**](/docs/connectors/mariadb-connector-nodejs/mariadb-connector-node-js-guide.md) **page**
{% endhint %}

## Bug Fixes

* [CONJS-349](https://jira.mariadb.org/browse/CONJS-349) Fix cleartext password disclosure to a man-in-the-middle when using fingerprint validation
* [CONJS-350](https://jira.mariadb.org/browse/CONJS-350) Possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
* [CONJS-351](https://jira.mariadb.org/browse/CONJS-351) Use constant-time comparison when validating the server certificate fingerprint, preventing a timing side-channel that could leak the token to a man-in-the-middle
* [CONJS-353](https://jira.mariadb.org/browse/CONJS-353) PAM (dialog) authentication now requires a secure connection (TLS or a local unix socket), since it transmits the password in clear text
* [CONJS-354](https://jira.mariadb.org/browse/CONJS-354) Reject a server-initiated LOAD DATA LOCAL INFILE request when `permitLocalInfile` is disabled

<sub>*This page is: Copyright © 2025 MariaDB. All rights reserved.*</sub>

{% @marketo/form formid="4316" formId="4316" %}
