---
id: CVE-2026-88032
title: >-
  A use-after-free in the reactive client-side encryption component of the
  MongoDB Java Driver can cause native resources to be freed while an affected
  encrypted operation is still using them when the operation is cancelled
summary: >-
  A use-after-free in the reactive client-side encryption component of the
  MongoDB Java Driver can cause native resources to be freed while an affected
  encrypted operation is still using them when the operation is cancelled. A
  party able t…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-416
  - CWE-825
vendor: mongodb
product: java_driver
affected:
  - 'java_driver >= 4.2.0, < 5.11.1'
patched:
  - java_driver 5.11.1
published: '2026-09-10'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:51:16.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88032'
references:
  - url: 'https://jira.mongodb.org/browse/JAVA-6276'
    label: cna@mongodb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88032.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88032'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2531591'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88032'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88032'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00257
epssPercentile: 0.15485
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T18:28:34.186842Z'
ingestedAt: '2026-09-14T10:08:14.698Z'
---

## Overview

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.

## Affected

- `java_driver >= 4.2.0, < 5.11.1`

## Remediation

Upgrade past the affected range:

- `java_driver 5.11.1`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Quarkus · no fix planned: Exploit Intelligence, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Quarkus · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88032.json)
