VulnSea

c_driver vulnerabilities

CVEs whose affected-version data names the c_driver package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-93395Medium· 5.3
5d ago

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but doe…

SunlitMongoDB Inc. · C DriverEPSS 0.24%via NVD
CVE-2026-93394Low· 3.7
5d ago

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized par…

SunlitMongoDB Inc. · C DriverEPSS 0.19%via NVD
CVE-2026-93393High· 8.1
5d ago

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outsid…

TwilightMongoDB Inc. · C DriverEPSS 0.28%via NVD
CVE-2026-88036High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

Twilightmongodb · c_driverEPSS 0.26%via NVD
CVE-2026-88035Medium· 4.7
1w ago

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection setting…

Sunlitmongodb · c_driverEPSS 0.10%via NVD
CVE-2026-88026Medium· 6.5
1w ago

Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

SunlitMongoDB · C# DriverEPSS 0.22%via CVEORG
CVE-2026-88025High· 8.3
1w ago

GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

TwilightMongoDB · C# DriverEPSS 0.32%via CVEORG
CVE-2026-84969Low· 3.7
2w ago

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured leng…

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured leng…

Sunlitmongodb · c_driverEPSS 0.17%via NVD
c_driver vulnerabilities (CVEs) · VulnSea