Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-9100

Опубликовано: 20 мая 2026
Источник: debian
EPSS Низкий

Описание

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongo-c-driverfixed2.2.4-1package
mongo-c-driverfixed1.30.4-1+deb13u2trixiepackage
mongo-c-driverfixed1.23.1-1+deb12u3bookwormpackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-6281

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/5300219c09d53f361125066f57e05d0e392e56a1 (2.2.4)

  • Fixed by: https://github.com/mongodb/mongo-c-driver/commit/f70634e1d6d084f3b0f7077d03bde2d4cb95ce37 (1.30.8)

EPSS

Процентиль: 20%
0.00281
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
2 месяца назад

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

CVSS3: 5.9
nvd
2 месяца назад

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

CVSS3: 5.9
github
2 месяца назад

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

EPSS

Процентиль: 20%
0.00281
Низкий