基于 MongoDB Entity Framework Core 构建的应用程序,如果在连接字符串中指定了数据库名称,可能会意外地禁用字段级加密。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.3.1< 8.4.4 |
affected |
9.0.1< 9.1.4 |
affected | ||
10.0.0< 10.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.3.1 ~ 8.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93393 | 8.1 HIGH | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
| CVE-2026-92756 | 5.5 MEDIUM | Combining encryption settings may disable encryption |
| CVE-2026-92758 | 5.5 MEDIUM | Logs may collect sensitive information |
| CVE-2026-93395 | 5.3 MEDIUM | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
| CVE-2026-93394 | 3.7 LOW | libmongoc SCRAM client nonce-validation bypass |
No comments yet