Search CVE reports


Toggle filters

1 – 10 of 15 results


CVE-2026-84969

Medium priority
Needs evaluation

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84965

Medium priority
Needs evaluation

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84964

Medium priority
Needs evaluation

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84963

Medium priority
Needs evaluation

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-81524

Medium priority
Needs evaluation

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-9100

Medium priority
Needs evaluation

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-6691

Medium priority
Needs evaluation

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-6231

Medium priority
Needs evaluation

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and...

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-4359

Medium priority
Needs evaluation

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

1 affected package

mongo-c-driver

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-12119

Medium priority
Needs evaluation

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

2 affected packages

mongo-c-driver, php-mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
php-mongodb Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages