CVE-2026-88033
- EPSS 0.26%
- Veröffentlicht 10.09.2026 18:04:01
- Zuletzt bearbeitet 16.09.2026 17:58:43
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An a...
CVE-2026-88032
- EPSS 0.15%
- Veröffentlicht 10.09.2026 18:02:13
- Zuletzt bearbeitet 16.09.2026 15:51:16
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such ...
CVE-2026-18710
- EPSS 0.11%
- Veröffentlicht 11.08.2026 22:00:07
- Zuletzt bearbeitet 25.09.2026 14:40:36
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part ...
CVE-2021-20328
- EPSS 0.43%
- Veröffentlicht 25.02.2021 17:15:28
- Zuletzt bearbeitet 21.11.2024 05:46:23
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active M...