CVE-2026-106430Medium· 5.9▾ SunlitThe MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An aut…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An authenticated actor who can influence a name passed by an affected application can cause the application to read distinct values from an unintended field or rename an unintended collection. These operations use the application's existing database credentials.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-5gj4-9gm7-2fx2Medium· 5.8Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
GHSA-g4qm-m288-5cp9Medium· 4.0Coraza has Cookie Parser Confusion
GHSA-x26q-wvhg-fh4mMedium· 4.0Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
GHSA-3wr7-993q-jrffMedium· 4.0Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
GHSA-w253-m66g-rx24Medium· 5.8Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
CVE-2026-106505High· 7.7Backstage is an open framework for building developer portals