MongoDB

C Driver

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 24.09.2026 15:51:15
  • Zuletzt bearbeitet 24.09.2026 21:04:40

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap b...

  • EPSS 0.24%
  • Veröffentlicht 17.09.2026 20:34:57
  • Zuletzt bearbeitet 25.09.2026 20:32:52

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify ...

  • EPSS 0.19%
  • Veröffentlicht 17.09.2026 20:31:27
  • Zuletzt bearbeitet 25.09.2026 20:33:17

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man...

  • EPSS 0.28%
  • Veröffentlicht 17.09.2026 20:26:38
  • Zuletzt bearbeitet 29.09.2026 19:17:54

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds ...

  • EPSS 0.26%
  • Veröffentlicht 10.09.2026 18:09:10
  • Zuletzt bearbeitet 16.09.2026 18:13:54

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An auth...

  • EPSS 0.1%
  • Veröffentlicht 10.09.2026 18:07:10
  • Zuletzt bearbeitet 16.09.2026 18:08:46

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause t...

  • EPSS 0.19%
  • Veröffentlicht 03.09.2026 15:03:13
  • Zuletzt bearbeitet 22.09.2026 16:22:04

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports...

  • EPSS 0.15%
  • Veröffentlicht 03.09.2026 15:02:20
  • Zuletzt bearbeitet 22.09.2026 16:19:25

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap objec...

  • EPSS 0.1%
  • Veröffentlicht 03.09.2026 15:01:21
  • Zuletzt bearbeitet 22.09.2026 16:00:19

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthent...

  • EPSS 0.17%
  • Veröffentlicht 03.09.2026 14:59:01
  • Zuletzt bearbeitet 10.09.2026 19:50:25

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A p...