{"id":"CVE-2026-106428","title":"An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message","summary":"An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this m…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:49:23.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106428","references":[{"url":"https://jira.mongodb.org/browse/CDRIVER-6370","label":"cna@mongodb.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.181Z","slug":"CVE-2026-106428","body":"## Overview\n\nAn out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}