Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88032— Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver

Quick assessment

Affected
MongoDB Java Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB Java 驱动程序中响应式客户端加密组件存在一个释放后使用(use-after-free)漏洞。当加密操作被取消时,原生资源可能在操作仍在使用时被释放。能够触发该操作被取消的一方,可能导致宿主应用程序进程终止。要触发此问题,需要采用一种特定的响应式加密配置,该配置按需获取 KMS(密钥管理服务)凭证。

CVSS 5.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
MongoDB Java Driver 4.2.0< 5.11.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88032

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver
Source: CVE Program / CVE List V5
Vulnerability Description
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB Java Driver 4.2.0 ~ 5.11.1 -

II. Public POCs for CVE-2026-88032

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88032

登录查看更多情报信息。

Other References for CVE-2026-88032 (1)

Same Patch Batch · MongoDB · 2026-09-10 · 15 CVEs total

CVE-2026-88024 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88023 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88025 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88030 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88029 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88034 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88033 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88036 8.3 HIGH GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD
CVE-2026-88031 8.1 HIGH GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver
CVE-2026-88022 7.7 HIGH Unauthorized document disclosure and deletion via query-operator injection in explicit equ
CVE-2026-88027 7.1 HIGH Mass deletion and overwrite of embedded documents via query-operator injection in embedded
CVE-2026-88026 6.5 MEDIUM Regular expression injection via unescaped characters in LINQ query translation in MongoDB
CVE-2026-88028 6.5 MEDIUM Unauthorized document disclosure via query-operator injection in polymorphic relation iden
CVE-2026-88035 4.7 MEDIUM Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo

IV. Related Vulnerabilities

V. Comments for CVE-2026-88032

No comments yet


Leave a comment