基于 MongoDB Entity Framework Core 提供者构建的应用程序,如果同时使用了独立的加密设置和该提供者自身的加密设置,可能会无声地丢失 TLS 和模式映射(schema-map)配置,从而导致受保护的字段以未加密的形式存储在数据库中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.0.0< 8.4.3 |
affected |
9.0.0< 9.1.3 |
affected | ||
10.0.0< 10.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.0.0 ~ 8.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93393 | 8.1 HIGH | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
| CVE-2026-92757 | 5.5 MEDIUM | Malformed connection string may disable field level encryption |
| CVE-2026-92758 | 5.5 MEDIUM | Logs may collect sensitive information |
| CVE-2026-93395 | 5.3 MEDIUM | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
| CVE-2026-93394 | 3.7 LOW | libmongoc SCRAM client nonce-validation bypass |
No comments yet