---
id: CVE-2026-81529
title: >-
  Improper neutralization of delimiters in connection-URL construction allows
  connection-option injection in the MongoDB C# Driver
summary: >-
  Improper neutralization of delimiters in connection-URL construction allows
  connection-option injection in the MongoDB C# Driver. When an application
  passes untrusted text into the driver's connection-URL builder and round-trips
  the buil…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-88
vendor: mongodb
product: c#_driver
affected:
  - 'c#_driver >= 2.10.0, < 3.11.1'
patched:
  - c#_driver 3.11.1
published: '2026-08-27'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:16:22.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81529'
references:
  - url: 'https://jira.mongodb.org/browse/CSHARP-6171'
    label: cna@mongodb.com
  - url: 'https://www.nuget.org/packages/MongoDB.Driver/3.11.1'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00278
epssPercentile: 0.1823
ingestedAt: '2026-09-29T19:44:04.118Z'
---

## Overview

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without neutralizing the URL/option delimiters and is then re-parsed as authoritative connection options. A low-privileged user of such an application can thereby introduce or suppress security-relevant connection settings.

## Affected

- `c#_driver >= 2.10.0, < 3.11.1`

## Remediation

Upgrade past the affected range:

- `c#_driver 3.11.1`
