CVE-2026-106430

NameCVE-2026-106430
DescriptionThe MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An authenticated actor who can influence a name passed by an affected application can cause the application to read distinct values from an unintended field or rename an unintended collection. These operations use the application's existing database credentials.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-cxx-driver (PTS)forky4.6.0-1vulnerable
sid4.6.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-cxx-driversource(unstable)4.6.1-1

Notes

https://jira.mongodb.org/browse/CXX-3551
https://jira.mongodb.org/browse/CXX-3552
Fixed by: https://github.com/mongodb/mongo-cxx-driver/commit/dabc8ff93b616747c64007183f04399d9636468d (4.6.0)
Fixed by: https://github.com/mongodb/mongo-cxx-driver/commit/5a6efb4ae260a3dd6d243a1a1b1e4d788e392416 (4.6.1)

Search for package or bug name: Reporting problems