CVE-2026-106438

NameCVE-2026-106438
DescriptionAn incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-c-driver (PTS)bookworm1.23.1-1+deb12u3vulnerable
trixie1.30.4-1+deb13u3vulnerable
forky2.5.5-1vulnerable
sid2.5.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-c-driversource(unstable)2.5.6-1

Notes

[trixie] - mongo-c-driver <no-dsa> (Minor issue)
https://jira.mongodb.org/browse/CDRIVER-6419
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/54a7e9f372bd8e1953298b60393b07b042360a87 (2.5.6)
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/12930599bad296e8a42042677478279fd9e903f7 (1.30.13)

Search for package or bug name: Reporting problems