CVE-2026-106433: MongoDB Libmongocrypt

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.

Affected products

  • MongoDB Libmongocrypt: from 1.1.0, before 1.20.5 (fixed in 1.20.5)

Published 2026-10-08. Last modified 2026-10-08.