在 MongoDB Rust 驱动的 GridFS 组件中,数据查询逻辑中对特殊元素的中和处理不当,导致调用方提供的结构化文件标识符可能被解释为查询条件,而不是作为字面量标识符处理。如果已认证的用户能够影响受影响应用程序传递的标识符,他们可能会获取超出预期目标的已存储文件内容,或者导致受影响存储桶中的所有 GridFS 文件块被删除,从而使已存储的文件内容无法读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | Rust Driver | 2.4.0< 3.9.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Rust Driver | 2.4.0 ~ 3.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88023 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88025 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88030 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88029 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88034 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88033 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88036 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88031 | 8.1 HIGH | GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver |
| CVE-2026-88022 | 7.7 HIGH | Unauthorized document disclosure and deletion via query-operator injection in explicit equ |
| CVE-2026-88027 | 7.1 HIGH | Mass deletion and overwrite of embedded documents via query-operator injection in embedded |
| CVE-2026-88026 | 6.5 MEDIUM | Regular expression injection via unescaped characters in LINQ query translation in MongoDB |
| CVE-2026-88028 | 6.5 MEDIUM | Unauthorized document disclosure via query-operator injection in polymorphic relation iden |
| CVE-2026-88032 | 5.9 MEDIUM | Application denial of service via cancellation race in reactive client-side encryption in |
| CVE-2026-88035 | 4.7 MEDIUM | Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo |
No comments yet