CVE-2026-93393
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | C Driver | 2.4.0 | affected |
| MongoDB Inc. | C Driver | 2.3.0 <= 2.3.3 | affected |
| MongoDB Inc. | C Driver | 2.2.0 <= 2.2.4 | affected |
| MongoDB Inc. | C Driver | 2.1.0 <= 2.1.2 | affected |
| MongoDB Inc. | C Driver | 2.0.0 <= 2.0.2 | affected |
| MongoDB Inc. | C Driver | 1.30.0 <= 1.30.8 | affected |
| MongoDB Inc. | C Driver | 1.29.0 <= 1.29.2 | affected |
| MongoDB Inc. | C Driver | 1.28.0 <= 1.28.1 | affected |
| MongoDB Inc. | C Driver | 1.27.0 <= 1.27.6 | affected |
| MongoDB Inc. | C Driver | 1.26.0 <= 1.26.2 | affected |
| MongoDB Inc. | C Driver | 1.25.0 <= 1.25.4 | affected |
| MongoDB Inc. | C Driver | 1.24.0 <= 1.24.4 | affected |
Weaknesses
- CWE-787: CWE-787: Out-of-bounds Write
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.