CVE-2026-4359
CVE-2026-4359 is a low-severity vulnerability in Mongodb C Driver with a CVSS 3.x base score of 2.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-158.
Key facts
- Severity: Low (CVSS 3.x base score 2.0)
- CVSS v4: 2.0
- EPSS exploit prediction: 0% (14th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-12640
- Weakness: CWE-158
- Affected product: Mongodb C Driver
- Published:
- Last modified:
Description
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
Frequently asked questions
- What is CVE-2026-4359?
- A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
- How severe is CVE-2026-4359?
- CVE-2026-4359 has a CVSS 3.x base score of 2.0, rated low severity. It is exploitable over network with high attack complexity, requires high privileges and user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-4359 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-4359?
- CVE-2026-4359 affects Mongodb C Driver. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-4359?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-4359 have an EU (EUVD) identifier?
- Yes. CVE-2026-4359 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-12640.
- When was CVE-2026-4359 published?
- CVE-2026-4359 was published on 2026-03-17 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
More vulnerabilities in Mongodb C Driver
- CVE-2026-88036 — High (CVSS 8.3): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can…
- CVE-2026-93393 — High (CVSS 8.1): A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows…
- CVE-2026-6691 — High (CVSS 7.8): The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling…
- CVE-2024-7553 — High (CVSS 7.3): Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the…
- CVE-2025-12119 — Medium (CVSS 6.8): A mongoc_bulk_operation_t may read invalid memory if large options are passed.
- CVE-2026-84964 — Medium (CVSS 5.9): A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a…
All CVEs affecting Mongodb C Driver →
Other CWE-158 vulnerabilities
- CVE-2025-47812 — Critical (CVSS 10.0): In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection…
- CVE-2025-14388 — Critical (CVSS 9.8): The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all…
- CVE-2025-55113 — Critical (CVSS 9.0): If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support…
- CVE-2023-5719 — High (CVSS 8.8): The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for…
- CVE-2009-1537 — High (CVSS 8.8): Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0…
- CVE-2025-9648 — High (CVSS 8.7): A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial…