๐Ÿ” CVE Alert

CVE-2026-96746

MEDIUM 6.5

Heap buffer overflow via mid-scan command list growth in client topology monitoring

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.

CWE CWE-787
Vendor mongodb
Product c driver
Ecosystems
Industries
Technology
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb c driver

Be the first to know when new medium vulnerabilities affecting mongodb c driver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

MongoDB / C Driver
0 < 1.30.12 2.0.0 < 2.5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.12 github.com: https://github.com/mongodb/mongo-c-driver/releases/tag/2.5.5