CVE-2026-84971: MongoDB Libmongocrypt

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.

Affected products

  • MongoDB Libmongocrypt: from 1.7.0, before 1.20.4 (fixed in 1.20.4)

Published 2026-09-03. Last modified 2026-09-17.