MongoDB C 驱动程序在处理 Decimal128 字符串解析时存在错误计算问题,该问题会接受包含前导零的某些高精度输入,而不是拒绝它们。这会导致解析出的值与输入的文本不一致。攻击者如果能够通过扩展 JSON 解析等途径,向嵌入式应用程序提供 Decimal 字符串,就可以使该应用程序存储或使用不正确的数值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106433 | 8.8 HIGH | Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt |
| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107325 | 5.9 MEDIUM | Application denial of service via missing BSON array length validation in MongoDB Go Drive |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106435 | 5.1 MEDIUM | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt |
| CVE-2026-106436 | 4.8 MEDIUM | Application denial of service and data truncation via unchecked BSON append failures in Mo |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
| CVE-2026-106432 | 3.6 LOW | Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver |
No comments yet