MongoDB Go 驱动中 GridFS 组件的数据查询逻辑中存在特殊元素未正确中和(即未正确过滤或转义)的缺陷,可能导致由调用方提供的结构化文件标识符被解析为查询条件,而非作为字面量标识符处理。能够影响受漏洞应用程序所传递的标识符的经过身份验证的用户,可能致使受影响存储桶中的所有 GridFS 文件块被删除,从而导致已存储的文件内容无法读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88024 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88023 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88025 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88030 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88029 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88034 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88033 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88036 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88022 | 7.7 HIGH | Unauthorized document disclosure and deletion via query-operator injection in explicit equ |
| CVE-2026-88027 | 7.1 HIGH | Mass deletion and overwrite of embedded documents via query-operator injection in embedded |
| CVE-2026-88026 | 6.5 MEDIUM | Regular expression injection via unescaped characters in LINQ query translation in MongoDB |
| CVE-2026-88028 | 6.5 MEDIUM | Unauthorized document disclosure via query-operator injection in polymorphic relation iden |
| CVE-2026-88032 | 5.9 MEDIUM | Application denial of service via cancellation race in reactive client-side encryption in |
| CVE-2026-88035 | 4.7 MEDIUM | Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo |
No comments yet