Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4359

Опубликовано: 17 мар. 2026
Источник: debian
EPSS Низкий

Описание

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongo-c-driverfixed2.2.3-1package
mongo-c-driverfixed1.30.4-1+deb13u2trixiepackage
mongo-c-driverfixed1.23.1-1+deb12u3bookwormpackage
mongo-c-driverpostponedbullseyepackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-6251

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/b93ebe6b99e614b49a24316c7a295eb3f08af603 (2.2.3)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/754232f3cffe924346dcf327f4a723f1a0839420 (1.30.8)

EPSS

Процентиль: 9%
0.00187
Низкий

Связанные уязвимости

CVSS3: 2
ubuntu
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

CVSS3: 5.9
redhat
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

CVSS3: 2
nvd
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

CVSS3: 2.2
redos
около 1 месяца назад

Уязвимость mongo-c-driver

CVSS3: 2
github
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

EPSS

Процентиль: 9%
0.00187
Низкий