CVE-2026-84971: MongoDB Libmongocrypt
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.
Affected products
- MongoDB Libmongocrypt: from 1.7.0, before 1.20.4 (fixed in 1.20.4)
Published 2026-09-03. Last modified 2026-09-17.