MongoDB C++ Driver
21 known vulnerabilities in MongoDB C++ Driver, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-96746 CVSS 8.3 high An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name…
- CVE-2026-93395 CVSS 6.9 medium A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data…
- CVE-2026-93394 CVSS 6.3 medium A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the…
- CVE-2026-93393 CVSS 9.2 critical A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A…
- CVE-2026-88036 CVSS 6.1 medium Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a…
- CVE-2026-88035 CVSS 5.7 medium A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is…
- CVE-2026-88034 CVSS 6.1 medium Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a…
- CVE-2026-88026 CVSS 7.1 high Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a…
- CVE-2026-88025 CVSS 6.1 medium Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a…
- CVE-2026-84966 CVSS 5.9 medium An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be…
- CVE-2026-84965 CVSS 5.9 medium An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a…
- CVE-2026-84964 CVSS 8.2 high A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that…
- CVE-2026-84963 CVSS 6.3 medium An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text…
- CVE-2026-84970 CVSS 5.9 medium A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the…
- CVE-2026-84969 CVSS 6.3 medium A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a…
- CVE-2026-81530 CVSS 6.8 medium A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential…
- CVE-2026-81529 CVSS 7.1 high Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an…
- CVE-2026-81528 CVSS 5.3 medium A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a…
- CVE-2026-81527 CVSS 6.9 medium A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both…
- CVE-2026-81524 CVSS 5.3 medium A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without…
- CVE-2026-81522 CVSS 8.6 high A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those…