MongoDB 的 libmongocrypt 库中存在状态管理不当的问题,可能导致在处理包含重复 masterKey 字段的密钥文档时,特定于提供程序的数据被错误地视为不兼容类型。具有权限修改密钥库文档的已认证用户,或返回此类密钥文档的服务器,可导致客户端进程发生无效内存访问和无效释放操作。这可能终止应用程序运行或损坏进程内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | libmongocrypt | 1.1.0< 1.20.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | libmongocrypt | 1.1.0 ~ 1.20.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107325 | 5.9 MEDIUM | Application denial of service via missing BSON array length validation in MongoDB Go Drive |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106435 | 5.1 MEDIUM | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt |
| CVE-2026-106436 | 4.8 MEDIUM | Application denial of service and data truncation via unchecked BSON append failures in Mo |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106438 | 4.0 MEDIUM | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
| CVE-2026-106432 | 3.6 LOW | Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver |
No comments yet