Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88035

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 4.7
CVSS3: 5.5
EPSS Низкий

Описание

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
Версия от 1.10.0 (включая) до 1.30.10 (исключая)
cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
Версия от 2.2.0 (включая) до 2.5.3 (исключая)

EPSS

Процентиль: 1%
0.00103
Низкий

4.7 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 4.7
ubuntu
8 дней назад

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

CVSS3: 4.7
debian
8 дней назад

A size check in the client-side authentication path of the MongoDB C D ...

CVSS3: 4.7
github
8 дней назад

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.

EPSS

Процентиль: 1%
0.00103
Низкий

4.7 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-190