CVE-2026-96746
- EPSS 0.37%
- Veröffentlicht 24.09.2026 15:51:15
- Zuletzt bearbeitet 24.09.2026 21:04:40
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap b...
CVE-2026-93395
- EPSS 0.24%
- Veröffentlicht 17.09.2026 20:34:57
- Zuletzt bearbeitet 25.09.2026 20:32:52
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify ...
CVE-2026-93394
- EPSS 0.19%
- Veröffentlicht 17.09.2026 20:31:27
- Zuletzt bearbeitet 25.09.2026 20:33:17
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man...
CVE-2026-93393
- EPSS 0.28%
- Veröffentlicht 17.09.2026 20:26:38
- Zuletzt bearbeitet 29.09.2026 19:17:54
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds ...
CVE-2026-88036
- EPSS 0.26%
- Veröffentlicht 10.09.2026 18:09:10
- Zuletzt bearbeitet 16.09.2026 18:13:54
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An auth...
CVE-2026-88035
- EPSS 0.1%
- Veröffentlicht 10.09.2026 18:07:10
- Zuletzt bearbeitet 16.09.2026 18:08:46
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause t...
CVE-2026-84963
- EPSS 0.19%
- Veröffentlicht 03.09.2026 15:03:13
- Zuletzt bearbeitet 22.09.2026 16:22:04
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports...
CVE-2026-84964
- EPSS 0.15%
- Veröffentlicht 03.09.2026 15:02:20
- Zuletzt bearbeitet 22.09.2026 16:19:25
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap objec...
CVE-2026-84965
- EPSS 0.1%
- Veröffentlicht 03.09.2026 15:01:21
- Zuletzt bearbeitet 22.09.2026 16:00:19
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthent...
CVE-2026-84969
- EPSS 0.17%
- Veröffentlicht 03.09.2026 14:59:01
- Zuletzt bearbeitet 10.09.2026 19:50:25
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A p...