MongoDB / C Driver
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96746 | Heap buffer overflow via mid-scan command list growth in client topology monitoring | HIGH | 8.3 | Sep 24, 2026 |
| CVE-2026-93395 | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() | MEDIUM | 6.9 | Sep 17, 2026 |
| CVE-2026-93394 | libmongoc SCRAM client nonce-validation bypass | MEDIUM | 6.3 | Sep 17, 2026 |
| CVE-2026-93393 | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream | CRITICAL | 9.2 | Sep 17, 2026 |
| CVE-2026-88036 | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver | MEDIUM | 6.1 | Sep 10, 2026 |
| CVE-2026-88035 | Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver | MEDIUM | 5.7 | Sep 10, 2026 |
| CVE-2026-84963 | Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser | MEDIUM | 6.3 | Sep 3, 2026 |
| CVE-2026-84964 | Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client | HIGH | 8.2 | Sep 3, 2026 |
| CVE-2026-84965 | Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds | MEDIUM | 5.9 | Sep 3, 2026 |
| CVE-2026-84969 | Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output | MEDIUM | 6.3 | Sep 3, 2026 |
| CVE-2026-81524 | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-9100 | Heap memory out of bounds read and crash in C Driver legacy GridFS file reader | MEDIUM | 6.0 | May 20, 2026 |
| CVE-2026-6691 | MongoDB C Driver Cyrus SASL Canonicalization Buffer Overflow | HIGH | 8.6 | May 6, 2026 |
| CVE-2026-6231 | bson_validate may skip validation when processing certain inputs | MEDIUM | 5.3 | Apr 13, 2026 |
| CVE-2026-4359 | Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer | LOW | 2.0 | Mar 17, 2026 |
| CVE-2025-12119 | Bulk write with options may read invalid memory | MEDIUM | 6.9 | Nov 18, 2025 |
| CVE-2024-7553 | Accessing Untrusted Directory May Allow Local Privilege Escalation | HIGH | 7.8 | Aug 7, 2024 |
| CVE-2023-0437 | MongoDB client C Driver may infinitely loop when validating certain BSON input data | HIGH | 7.5 | Jan 12, 2024 |
| CVE-2021-32050 | Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application | HIGH | 7.5 | Aug 29, 2023 |
| CVE-2020-12135 | bson: integer overflow in bson_ensure_space() parameter bytesNeeded | MEDIUM | 5.5 | Apr 24, 2020 |
Showing 1 to 14 of 14 CVEs