Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-93395

Medium priority
Needs evaluation

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93394

Medium priority
Needs evaluation

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message....

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93393

Medium priority
Needs evaluation

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-88036

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84965

Medium priority
Needs evaluation

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84964

Medium priority
Needs evaluation

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84963

Medium priority
Needs evaluation

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84969

Medium priority
Needs evaluation

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-81524

Medium priority
Needs evaluation

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-9100

Medium priority
Needs evaluation

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages