Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81521

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.

A flaw was found in the MongoDB Go Driver. The Client.BulkWrite operation does not properly validate database names, allowing a specially crafted name with reserved characters to redirect write operations. This vulnerability could enable an attacker to modify or corrupt data in unintended databases and collections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientAffected
OpenShift Pipelinesopenshift-pipelines/pipelines-chains-controller-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-chains-controller-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Affected
Red Hat Edge Manager 1flightctlAffected
Red Hat Edge Manager 1rhem/flightctl-alert-exporter-rhel10Affected
Red Hat Edge Manager 1rhem/flightctl-alert-exporter-rhel9Affected
Red Hat Edge Manager 1rhem/flightctl-alertmanager-proxy-rhel10Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-791
https://bugzilla.redhat.com/show_bug.cgi?id=2525215go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
20 дней назад

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.

CVSS3: 6.5
nvd
20 дней назад

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.

CVSS3: 6.5
debian
20 дней назад

The MongoDB Go Driver's client-level bulk write operation may accept a ...

7.5 High

CVSS3