Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-88035

Опубликовано: 10 сент. 2026
Источник: debian
EPSS Низкий

Описание

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongo-c-driverfixed2.5.3-1package
mongo-c-driverno-dsatrixiepackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-6416

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/ddfe9e5fe9e3e43ce8f3b1429cacc872767ee2ba (2.5.3)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01245bbd8888946ec54c8faadcb5f40670592d26 (1.3.10)

EPSS

Процентиль: 1%
0.00103
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
8 дней назад

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

CVSS3: 4.7
nvd
8 дней назад

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

CVSS3: 4.7
github
7 дней назад

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

EPSS

Процентиль: 1%
0.00103
Низкий