---
id: CVE-2026-106429
title: >-
  An integer underflow in the KMS endpoint-parsing logic of MongoDB
  libmongocrypt can cause an allocation failure that terminates the application
  process
summary: >-
  An integer underflow in the KMS endpoint-parsing logic of MongoDB
  libmongocrypt can cause an allocation failure that terminates the application
  process. This can occur when an authenticated user modifies a key document in
  the key vault c…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-191
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:49:23.240'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106429'
references:
  - url: 'https://jira.mongodb.org/browse/MONGOCRYPT-986'
    label: cna@mongodb.com
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.181Z'
---

## Overview

An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
