CVE-2026-84969: MongoDB C Driver
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the application that links the driver, may cause a small amount of data outside the intended buffer to be altered.
Affected products
- MongoDB C Driver: from 1.30.0, before 1.30.9 (fixed in 1.30.9); from 2.0.0, before 2.5.2 (fixed in 2.5.2)
Published 2026-09-03. Last modified 2026-09-10.