Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106430— Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver

Quick assessment

Affected
MongoDB C++ Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB C++ 驱动程序在处理由集合 API 接受的某些字段名和集合名时,会丢弃嵌入的 NUL 字节之后的内容。这可能导致驱动程序与被调用的应用程序对同一名称产生不同的解释。经过身份验证的攻击者若能够影响受影响的传入应用程序中的名称,可使该应用程序从非预期的字段中读取不同的值,或重命名非预期的集合。这些操作均使用应用程序现有的数据库凭据执行。

CVSS 5.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
MongoDB C++ Driver 3.0.0< 4.6.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106430

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver
Source: CVE Program / CVE List V5
Vulnerability Description
The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An authenticated actor who can influence a name passed by an affected application can cause the application to read distinct values from an unintended field or rename an unintended collection. These operations use the application's existing database credentials.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
解释冲突
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB C++ Driver 3.0.0 ~ 4.6.1 -

II. Public POCs for CVE-2026-106430

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106430

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-106430 (1)

Other References for CVE-2026-106430 (1)

Same Patch Batch · MongoDB · 2026-10-08 · 13 CVEs total

CVE-2026-106433 8.8 HIGH Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt
CVE-2026-106429 6.5 MEDIUM Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt
CVE-2026-106437 6.2 MEDIUM Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver
CVE-2026-107325 5.9 MEDIUM Application denial of service via missing BSON array length validation in MongoDB Go Drive
CVE-2026-107324 5.9 MEDIUM Application denial of service via integer overflow in BSON value-length validation in Mong
CVE-2026-106431 5.7 MEDIUM One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver
CVE-2026-106435 5.1 MEDIUM Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt
CVE-2026-106436 4.8 MEDIUM Application denial of service and data truncation via unchecked BSON append failures in Mo
CVE-2026-106434 4.3 MEDIUM Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt
CVE-2026-106438 4.0 MEDIUM Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver
CVE-2026-106428 3.7 LOW Out-of-bounds read in SCRAM response parsing in MongoDB C Driver
CVE-2026-106432 3.6 LOW Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver

IV. Related Vulnerabilities

V. Comments for CVE-2026-106430

No comments yet


Leave a comment