Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer
Published Mar 17, 2026
2.0
LOWCVSS 4.0
EPSS 0.24%
Description
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
Affected products
-
- Version 0StatusaffectedConstraints<2.2.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc | MongoDB C Driver | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This LOW impact vulnerability in the MongoDB C driver allows denial of service via malformed HTTP responses. Exploitation requires high complexity—either a compromised cloud server or active MITM position. Impact is limited to availability. Applications are only vulnerable when connecting to untrusted MongoDB instances or over untrusted networks.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-4359 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448447 Issue Tracking
- https://jira.mongodb.org/browse/CDRIVER-6251 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4359
- https://www.cve.org/CVERecord?id=CVE-2026-4359
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-4359 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2448447 | Issue Tracking | |
| https://jira.mongodb.org/browse/CDRIVER-6251 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-4359 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-4359 |
Change history (0)
No recorded changes yet.