CVE-2026-106433: MongoDB Libmongocrypt
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.
Affected products
- MongoDB Libmongocrypt: from 1.1.0, before 1.20.5 (fixed in 1.20.5)
Published 2026-10-08. Last modified 2026-10-08.