« Volver al listado

Mongodb

Mongodb C Driver: vulnerabilidades y CVE

Mongodb C Driver tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses16
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96746Alta (8.3)0.37%—24 sept 2026
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to…
CVE-2026-93395Media (6.9)0.40%—17 sept 2026
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the…
CVE-2026-93394Media (6.3)0.32%—17 sept 2026
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message.…
CVE-2026-93393Crítica (9.2)0.47%—17 sept 2026
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write…
CVE-2026-88036Media (6.1)0.27%—10 sept 2026
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than…
CVE-2026-88035Media (5.7)0.10%—10 sept 2026
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's…
CVE-2026-84965Media (5.9)0.13%—3 sept 2026
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where…
CVE-2026-84964Alta (8.2)0.26%—3 sept 2026
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate…
CVE-2026-84963Media (6.3)0.31%—3 sept 2026
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the…
CVE-2026-84969Media (6.3)0.27%—3 sept 2026
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a…
CVE-2026-81524Media (5.3)0.27%—27 ago 2026
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An…
CVE-2026-9100Media (6)0.30%—20 may 2026
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the…
CVE-2026-6691Alta (8.6)0.18%—6 may 2026
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by…
CVE-2026-6231Media (5.3)0.32%—13 abr 2026
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass…
CVE-2026-4359Baja (2)0.24%—17 mar 2026
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
CVE-2025-12119Media (6.9)0.20%—18 nov 2025
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2024-7553Alta (7.8)0.26%—7 ago 2024
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour…
CVE-2024-6383Media (5.3)0.63%—3 jul 2024
The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory.…
CVE-2023-0437Alta (7.5)1.1%—12 ene 2024
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.
CVE-2021-32050Alta (7.5)0.65%—29 ago 2023
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific…
CVE-2020-12135Media (5.5)1.2%—24 abr 2020
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1499.004 Application or System Exploitation2
  3. T1059.007 JavaScript1
  4. T1212 Exploitation for Credential Access1
  5. T1557 Adversary-in-the-Middle1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mongodb