CVE-2026-84970Medium· 6.2▾ SunlitA numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that tex…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.10%
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer and return it to the caller, to silently accept only part of the input as a complete document, or to terminate the process. No MongoDB server, credentials, or non-default configuration is required; the effect is confined to the process that uses the library.
c++_driver >= 3.2.0, < 4.5.2Upgrade past the affected range:
c++_driver 4.5.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88034High· 8.3Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…
CVE-2026-13062Medium· 6.5MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
CVE-2026-13060Medium· 6.5$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access
CVE-2026-76798Medium· 6.3The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context
CVE-2026-76797Medium· 6.3The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas
CVE-2026-76794Medium· 4.6MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML