🔐 CVE Alert

CVE-2026-93393

HIGH 8.1

Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.

CWE CWE-787
Vendor mongodb inc.
Product c driver
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb inc. c driver

Be the first to know when new high vulnerabilities affecting mongodb inc. c driver are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MongoDB Inc. / C Driver
2.4.0 2.3.0 ≤ 2.3.3 2.2.0 ≤ 2.2.4 2.1.0 ≤ 2.1.2 2.0.0 ≤ 2.0.2 1.30.0 ≤ 1.30.8 1.29.0 ≤ 1.29.2 1.28.0 ≤ 1.28.1 1.27.0 ≤ 1.27.6 1.26.0 ≤ 1.26.2 1.25.0 ≤ 1.25.4 1.24.0 ≤ 1.24.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
jira.mongodb.org: https://jira.mongodb.org/browse/CDRIVER-6417