{"id":"CVE-2026-106438","title":"An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them","summary":"An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor w…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-682"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:49:23.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106438","references":[{"url":"https://jira.mongodb.org/browse/CDRIVER-6419","label":"cna@mongodb.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.184Z","slug":"CVE-2026-106438","body":"## Overview\n\nAn incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}