Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r6x-hxgf-2vcw

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 5.3

Описание

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

EPSS

Процентиль: 3%
0.00133
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

CVSS3: 5.3
nvd
около 1 месяца назад

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

CVSS3: 5.3
debian
около 1 месяца назад

A MongoDB server initiating an outbound TLS connection may terminate a ...

EPSS

Процентиль: 3%
0.00133
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-476