Back

MEDIUM

Heap memory out of bounds read and crash in C Driver legacy GridFS file reader

Published May 20, 2026

Description

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mongodb
Published May 20, 2026
Updated May 20, 2026
Reserved May 20, 2026

CISA Vulnrichment

Updated May 20, 2026

NVD

Status Undergoing Analysis
Modified Jul 23, 2026

Red Hat

No data

ENISA EUVD

Assigner mongodb
Published May 20, 2026
Updated May 20, 2026

GitHub

No data