CVE-2026-106438: MongoDB C Driver

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.

Affected products

  • MongoDB C Driver: from 1.4.0, before 1.30.13 (fixed in 1.30.13); from 2.0.0, before 2.5.6 (fixed in 2.5.6)

Published 2026-10-08. Last modified 2026-10-08.