Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Thu, 24 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly. | |
| Title | Heap buffer overflow via mid-scan command list growth in client topology monitoring | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-24T18:18:08.886Z
Reserved: 2026-09-23T15:45:49.685Z
Link: CVE-2026-96746
Updated: 2026-09-24T17:10:27.887Z
Status : Received
Published: 2026-09-24T16:17:27.460
Modified: 2026-09-24T18:19:08.800
Link: CVE-2026-96746
No data.
OpenCVE Enrichment
No data.