CVE-2026-96746: MongoDB C Driver

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.

Affected products

  • MongoDB C Driver: before 1.30.12 (fixed in 1.30.12); from 2.0.0, before 2.5.5 (fixed in 2.5.5)

Published 2026-09-24. Last modified 2026-09-24.