CVE-2026-88031
- EPSS 0.26%
- Veröffentlicht 10.09.2026 17:59:35
- Zuletzt bearbeitet 29.09.2026 15:58:34
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An aut...
CVE-2026-81521
- EPSS 0.2%
- Veröffentlicht 27.08.2026 18:31:45
- Zuletzt bearbeitet 06.10.2026 19:18:15
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application...
CVE-2026-2303
- EPSS 0.22%
- Veröffentlicht 10.02.2026 19:03:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the G...
CVE-2021-20329
- EPSS 0.96%
- Veröffentlicht 10.06.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:23
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This ...