VulnSea

c#_driver vulnerabilities

CVEs whose affected-version data names the c#_driver package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-88026Medium· 6.5
2w ago

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

▾ Sunlitmongodb · c#_driverEPSS 0.37%via NVD
CVE-2026-88025High· 8.3
2w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

▾ Twilightmongodb · c#_driverEPSS 0.46%via NVD
CVE-2026-81530Medium· 5.6
1mo ago

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic r…

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic r…

▾ Sunlitmongodb · c#_driverEPSS 0.09%via NVD
CVE-2026-81529High· 7.1
1mo ago

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the buil…

▾ Twilightmongodb · c#_driverEPSS 0.28%via NVD
CVE-2026-81528Medium· 5.4
1mo ago

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language sp…

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server without neutralization of query-language sp…

▾ Sunlitmongodb · c#_driverEPSS 0.27%via NVD
CVE-2026-81527Medium· 6.5
1mo ago

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certa…

▾ Sunlitmongodb · c#_driverEPSS 0.31%via NVD
c#_driver vulnerabilities (CVEs) · VulnSea