MongoDB C驱动程序中 GridFS 组件在数据查询逻辑中对特殊元素的中和(转义/处理)不当,可能导致调用方提供的结构化文件标识符被解释为查询条件,而非作为字面量标识符处理。一个能够影响受受影响应用程序传入标识符的已认证用户,可能会获取超出预期目标范围的已存储文件内容,或者导致受影响桶中的所有 GridFS 文件分片被删除,从而使已存储的文件内容变得不可读。受影响的“重命名”操作还可能会重命名除预期目标之外的其他已存储文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88024 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88023 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88030 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88029 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88034 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88033 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88036 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88031 | 8.1 HIGH | GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver |
| CVE-2026-88022 | 7.7 HIGH | Unauthorized document disclosure and deletion via query-operator injection in explicit equ |
| CVE-2026-88027 | 7.1 HIGH | Mass deletion and overwrite of embedded documents via query-operator injection in embedded |
| CVE-2026-88026 | 6.5 MEDIUM | Regular expression injection via unescaped characters in LINQ query translation in MongoDB |
| CVE-2026-88028 | 6.5 MEDIUM | Unauthorized document disclosure via query-operator injection in polymorphic relation iden |
| CVE-2026-88032 | 5.9 MEDIUM | Application denial of service via cancellation race in reactive client-side encryption in |
| CVE-2026-88035 | 4.7 MEDIUM | Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo |
No comments yet