> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/release-notes/connectors/node.js/changelogs/3.x/3.3.4.md).

# Connector/Node.js 3.3.4 Changelog

<a href="https://mariadb.com/downloads/connectors/connectors-data-access/nodejs-connector" class="button primary">Download</a> <a href="/pages/MHxhvYUNrJW9uLM4JfMO" class="button secondary">Release Notes</a> <a href="/pages/YTqLPDi3WwmFlrR5bPbS" class="button secondary">Changelog</a> <a href="/spaces/CjGYMsT2MVP4nd3IyW2L/pages/x5uWNz6Wb26ooKT9S74U" class="button secondary">Connector/Node.js Overview</a>

**Release date:** 7 Aug 2026

For the highlights of this release, see the [release notes](/docs/release-notes/connectors/node.js/3.x/3.3.4.md).

The revision number links will take you to the revision's page on GitHub. On [GitHub](https://github.com/MariaDB/mariadb-connector-nodejs) you can view more details of the revision and view diffs of the code modified in that revision.

* [Revision #ee9b296](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/ee9b296) - bump 3.3.4 version
* [Revision #b9b04ec](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec) - \[[CONJS-369](https://jira.mariadb.org/browse/CONJS-369)] Object keys interpolated as identifiers without escapeId in SET expansion
* [Revision #e5a9d73](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d73) - \[[CONJS-368](https://jira.mariadb.org/browse/CONJS-368)] SQL injection in text protocol when session uses NO\_BACKSLASH\_ESCAPES
* [Revision #faa27d1](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1) - \[[CONJS-367](https://jira.mariadb.org/browse/CONJS-367)] Uninitialized process memory leaked to server via malformed GeoJSON Polygon parameter
* [Revision #194ab03](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/194ab03) - \[[CONJS-363](https://jira.mariadb.org/browse/CONJS-363)] typeCast accessors return corrupted values with prepared statements
* [Revision #02d1e28](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/02d1e28) - \[[CONJS-358](https://jira.mariadb.org/browse/CONJS-358)] Refuse multi-part packet reassembly before authentication
* [Revision #b8ddb83](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b8ddb83) - \[misc] test correction
* [Revision #10f8c22](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/10f8c22) - \[misc] correct CodeQL false positive
* [Revision #e775503](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e775503) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] use codeql v4
* [Revision #c5ed446](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/c5ed446) - \[misc] test correction for restrictedAuth
* [Revision #c3b303e](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/c3b303e) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] Harden connection-string parsing on maintenance
* [Revision #9b008d7](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/9b008d7) - \[[CONJS-357](https://jira.mariadb.org/browse/CONJS-357)] Add JavaScript SAST: CodeQL workflow + eslint-plugin-security with CI lint gate
* [Revision #2a58983](https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2a58983) - \[misc] Escape server-supplied filename before building LOCAL INFILE validation regex

<sub>*This page is: Copyright © 2026 MariaDB. All rights reserved.*</sub>

{% @marketo/form formid="4316" formId="4316" %}
