如果日志模式设置为 DEBUG,或者使用了格式错误的 MongoDB 连接字符串,应用程序日志可能会收集敏感信息(如果正在使用),例如密码和 AWS 安全访问密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.0.0< 8.4.4 |
affected |
9.0.0< 9.1.4 |
affected | ||
10.0.0< 10.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | MongoDB Entity Framework Core Provider | 8.0.0 ~ 8.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93393 | 8.1 HIGH | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
| CVE-2026-92756 | 5.5 MEDIUM | Combining encryption settings may disable encryption |
| CVE-2026-92757 | 5.5 MEDIUM | Malformed connection string may disable field level encryption |
| CVE-2026-93395 | 5.3 MEDIUM | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
| CVE-2026-93394 | 3.7 LOW | libmongoc SCRAM client nonce-validation bypass |
No comments yet