MongoDB C驱动程序中客户端加密配置层的缺陷,会导致应用提供的敏感密钥管理凭据在驱动对其客户端设置的人类可读诊断表示中按原样复现,而未被像其他机密字段那样进行掩码处理。因此,能够读取应用日志、诊断输出或进程内存转储的一方,可能会恢复明文凭据,并利用它们来解密受保护的字段数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81522 | 8.1 HIGH | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Dr |
| CVE-2026-81525 | 8.1 HIGH | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Dr |
| CVE-2026-81529 | 7.1 HIGH | Connection-option injection via unescaped settings in the canonical MongoDB URL builder |
| CVE-2026-81521 | 6.5 MEDIUM | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite |
| CVE-2026-81527 | 6.5 MEDIUM | NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation |
| CVE-2026-81526 | 6.5 MEDIUM | Cross-database write redirection via unvalidated dotted database name in bulk write namesp |
| CVE-2026-75159 | 5.9 MEDIUM | MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Ca |
| CVE-2026-81528 | 5.4 MEDIUM | NoSQL injection via array replacement bypassing update shape validation in driver write pa |
| CVE-2026-81524 | 5.4 MEDIUM | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driv |
| CVE-2026-75573 | 4.4 MEDIUM | MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Ar |
| CVE-2026-81523 | 4.4 MEDIUM | Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocr |
No comments yet