Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6231

Опубликовано: 13 апр. 2026
Источник: debian
EPSS Низкий

Описание

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongo-c-driverfixed2.1.0-1package
mongo-c-driverfixed1.30.4-1+deb13u2trixiepackage
mongo-c-driverfixed1.23.1-1+deb12u3bookwormpackage
mongo-c-driverpostponedbullseyepackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-6017

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/d184525513e5bf21f30810c00d6b0094aac8b00c (2.1.0)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/9fd3ec04b433f2f62b267e5b3868dd8d538245eb (2.1.0)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/ea3559687c5fc9c566b376299a3b43443a9c7f96 (2.1.0)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/40b673787060a80ef7f4875ae776cb4731dadec9 (1.30.5)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/017e630199cd006e01288b241774168b7d2b8bdf (1.30.5)

EPSS

Процентиль: 8%
0.00184
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1

CVSS3: 4.3
nvd
4 месяца назад

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1

CVSS3: 4.3
github
4 месяца назад

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1

CVSS3: 4.3
fstec
4 месяца назад

Уязвимость функции bson_validate() системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
redos
3 месяца назад

Уязвимость mongo-c-driver

EPSS

Процентиль: 8%
0.00184
Низкий