CVE-2026-81524

NameCVE-2026-81524
DescriptionA weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-c-driver (PTS)bullseye1.17.6-1vulnerable
bullseye (security)1.17.6-1+deb11u2vulnerable
bookworm1.23.1-1+deb12u3vulnerable
trixie1.30.4-1+deb13u2vulnerable
forky2.5.0-1vulnerable
sid2.5.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-c-driversource(unstable)2.5.1-1

Notes

[trixie] - mongo-c-driver <no-dsa> (Minor issue)
https://jira.mongodb.org/browse/CDRIVER-6424

Search for package or bug name: Reporting problems