CVE-2026-4359: MongoDB C Driver

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

Affected products

  • MongoDB C Driver: before 1.30.8 (fixed in 1.30.8); from 2.2.0, before 2.2.3 (fixed in 2.2.3)

Published 2026-03-17. Last modified 2026-06-17.