Mongodb
Mongodb C Driver: vulnerabilidades y CVE
Mongodb C Driver tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses16
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96746 | Alta (8.3) | 0.37% | — | 24 sept 2026 | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to… |
| CVE-2026-93395 | Media (6.9) | 0.40% | — | 17 sept 2026 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the… |
| CVE-2026-93394 | Media (6.3) | 0.32% | — | 17 sept 2026 | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message.… |
| CVE-2026-93393 | Crítica (9.2) | 0.47% | — | 17 sept 2026 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write… |
| CVE-2026-88036 | Media (6.1) | 0.27% | — | 10 sept 2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than… |
| CVE-2026-88035 | Media (5.7) | 0.10% | — | 10 sept 2026 | A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's… |
| CVE-2026-84965 | Media (5.9) | 0.13% | — | 3 sept 2026 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where… |
| CVE-2026-84964 | Alta (8.2) | 0.26% | — | 3 sept 2026 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate… |
| CVE-2026-84963 | Media (6.3) | 0.31% | — | 3 sept 2026 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the… |
| CVE-2026-84969 | Media (6.3) | 0.27% | — | 3 sept 2026 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a… |
| CVE-2026-81524 | Media (5.3) | 0.27% | — | 27 ago 2026 | A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An… |
| CVE-2026-9100 | Media (6) | 0.30% | — | 20 may 2026 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the… |
| CVE-2026-6691 | Alta (8.6) | 0.18% | — | 6 may 2026 | The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by… |
| CVE-2026-6231 | Media (5.3) | 0.32% | — | 13 abr 2026 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass… |
| CVE-2026-4359 | Baja (2) | 0.24% | — | 17 mar 2026 | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. |
| CVE-2025-12119 | Media (6.9) | 0.20% | — | 18 nov 2025 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. |
| CVE-2024-7553 | Alta (7.8) | 0.26% | — | 7 ago 2024 | Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour… |
| CVE-2024-6383 | Media (5.3) | 0.63% | — | 3 jul 2024 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory.… |
| CVE-2023-0437 | Alta (7.5) | 1.1% | — | 12 ene 2024 | When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0. |
| CVE-2021-32050 | Alta (7.5) | 0.65% | — | 29 ago 2023 | Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific… |
| CVE-2020-12135 | Media (5.5) | 1.2% | — | 24 abr 2020 | bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.