CVE-2026-9100: MongoDB C Driver

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

Affected products

  • MongoDB C Driver: from 1.10.0, before 1.30.8 (fixed in 1.30.8); from 2.0.0, before 2.2.4 (fixed in 2.2.4)

Published 2026-05-20. Last modified 2026-09-24.