---
id: CVE-2026-88031
title: >-
  Improper neutralization of special elements in data query logic in the GridFS
  component of the MongoDB Go Driver can cause a caller-supplied structured file
  identifier to be interpreted as a query condition rather than as a literal
  ident…
summary: >-
  Improper neutralization of special elements in data query logic in the GridFS
  component of the MongoDB Go Driver can cause a caller-supplied structured file
  identifier to be interpreted as a query condition rather than as a literal
  ident…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-943
  - CWE-1287
vendor: MongoDB
product: Go Driver
affected:
  - go_driver >= 1.0.0 < 1.17.10
  - go_driver >= 2.0.0 < 2.9.1
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:54:25.810'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88031'
references:
  - url: 'https://jira.mongodb.org/browse/GODRIVER-4081'
    label: cna@mongodb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88031.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88031'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2531587'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88031'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88031'
  - url: >-
      https://www.mongodb.com/community/forums/t/mongodb-go-driver-1-17-10-released/343342
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T18:25:51.598529Z'
ingestedAt: '2026-09-13T09:36:03.041Z'
epss: 0.00469
epssPercentile: 0.37976
---

## Overview

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Compliance Operator, Cryostat 4, ExternalDNS Operator, File Integrity Operator, Lightspeed Core, … · no fix planned: MCP Server for Red Hat OpenShift, OpenShift Lightspeed, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Developer Hub, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88031.json)
