Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4359

Опубликовано: 17 мар. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

A flaw was found in mongo-c-driver. A compromised third-party cloud server or a man-in-the-middle (MITM) attacker could send a malformed HTTP response. This could cause applications using the MongoDB C driver to crash, leading to a Denial of Service.

Отчет

This LOW impact vulnerability in the MongoDB C driver allows denial of service via malformed HTTP responses. Exploitation requires high complexity—either a compromised cloud server or active MITM position. Impact is limited to availability. Applications are only vulnerable when connecting to untrusted MongoDB instances or over untrusted networks.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2448447mongo-c-driver: mongo-c-driver: Denial of Service via malformed HTTP response

EPSS

Процентиль: 9%
0.00187
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 2
ubuntu
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

CVSS3: 2
nvd
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

CVSS3: 2
debian
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker c ...

CVSS3: 2.2
redos
около 1 месяца назад

Уязвимость mongo-c-driver

CVSS3: 2
github
5 месяцев назад

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

EPSS

Процентиль: 9%
0.00187
Низкий

5.9 Medium

CVSS3