CVE-2026-106428: MongoDB C Driver

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.

Affected products

  • MongoDB C Driver: from 1.1.0, before 1.30.13 (fixed in 1.30.13); from 2.0.0, before 2.4.0 (fixed in 2.4.0)

Published 2026-10-08. Last modified 2026-10-08.