Back

LOW

Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer

Published Mar 17, 2026

Description

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

Affected products

Remediation

Red Hat statement

This LOW impact vulnerability in the MongoDB C driver allows denial of service via malformed HTTP responses. Exploitation requires high complexity—either a compromised cloud server or active MITM position. Impact is limited to availability. Applications are only vulnerable when connecting to untrusted MongoDB instances or over untrusted networks.

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Mar 17, 2026
Updated Mar 18, 2026
Reserved Mar 17, 2026
CISA Vulnrichment
Updated Mar 18, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 17, 2026