MongoDB Go 驱动程序中存在对 BSON 数组长度的验证不当问题。当应用程序对格式错误的四字节数组调用 或 时,可能导致越界索引和运行时恐慌(panic)。未通过身份验证的攻击者若能为受影响的应用程序提供原始 BSON 数组数据,则可能终止未受保护的应用程序进程,从而引发拒绝服务(DoS)攻击。目前尚未发现任何对机密性或完整性的影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106433 | 8.8 HIGH | Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt |
| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106435 | 5.1 MEDIUM | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt |
| CVE-2026-106436 | 4.8 MEDIUM | Application denial of service and data truncation via unchecked BSON append failures in Mo |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106438 | 4.0 MEDIUM | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
| CVE-2026-106432 | 3.6 LOW | Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver |
No comments yet