Every CVE whose affected-product data names Mongodb C Driver, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (19)
CVE-2026-88036 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied…
CVE-2026-93393 — CVSS 8.1 (high): A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A…
CVE-2026-6691 — CVSS 7.8 (high): The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer…
CVE-2024-7553 — CVSS 7.3 (high): Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating…
CVE-2026-84964 — CVSS 5.9 (medium): A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that…
CVE-2026-9100 — CVSS 5.9 (medium): The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents…
CVE-2020-12135 — CVSS 5.5 (medium): bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the…
CVE-2026-81524 — CVSS 5.4 (medium): A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without…
CVE-2026-93395 — CVSS 5.3 (medium): A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data…
CVE-2023-0437 — CVSS 5.3 (medium): When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This…
CVE-2026-84963 — CVSS 5.3 (medium): An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text…
CVE-2026-84965 — CVSS 5.1 (medium): An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a…
CVE-2026-88035 — CVSS 4.7 (medium): A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is…
CVE-2026-6231 — CVSS 4.3 (medium): The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping…
CVE-2021-32050 — CVSS 4.2 (medium): Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an…
CVE-2026-84969 — CVSS 3.7 (low): A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a…
CVE-2026-93394 — CVSS 3.7 (low): A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the…
CVE-2026-4359 — CVSS 2.0 (low): A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications…