VendorsMongoDBc_driverany version
Vulnerabilities

MongoDB C Driver any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-6691
MongoDB C Driver Cyrus SASL Canonicalization Buffer Overflow
Published 2026-05-06 · Analyzed
8.6EPSS 0.001
CVE-2026-88036
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver
Published 2026-09-10 · Analyzed
8.3EPSS 0.003
CVE-2026-84964
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
Published 2026-09-03 · Analyzed
8.2EPSS 0.002
CVE-2024-7553
Accessing Untrusted Directory May Allow Local Privilege Escalation
Published 2024-08-07 · Analyzed
7.8EPSS 0.003
CVE-2023-0437
MongoDB client C Driver may infinitely loop when validating certain BSON input data
Published 2024-01-12 · Modified
7.5EPSS 0.011
CVE-2021-32050
Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application
Published 2023-08-29 · Modified
7.5EPSS 0.006
CVE-2026-6231
bson_validate may skip validation when processing certain inputs
Published 2026-04-13 · Analyzed
7.5EPSS 0.002
CVE-2025-12119
Bulk write with options may read invalid memory
Published 2025-11-18 · Modified
6.9EPSS 0.002
CVE-2026-84963
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
Published 2026-09-03 · Analyzed
6.3EPSS 0.002
CVE-2026-84969
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output
Published 2026-09-03 · Analyzed
6.3EPSS 0.002
CVE-2026-84965
Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
Published 2026-09-03 · Analyzed
5.9EPSS 0.001
CVE-2026-88035
Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver
Published 2026-09-10 · Analyzed
5.7EPSS 0.001
CVE-2020-12135
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
Published 2020-04-24 · Modified
5.5EPSS 0.012
CVE-2026-4359
Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer
Published 2026-03-17 · Analyzed
3.7EPSS 0.002