CVE-2026-96746: MongoDB C Driver
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.
Affected products
- MongoDB C Driver: before 1.30.12 (fixed in 1.30.12); from 2.0.0, before 2.5.5 (fixed in 2.5.5)
Published 2026-09-24. Last modified 2026-09-24.