CVE-2026-81524

NameCVE-2026-81524
DescriptionA weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-c-driver (PTS)bookworm1.23.1-1+deb12u3vulnerable
trixie1.30.4-1+deb13u3fixed
forky, sid2.5.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-c-driversourcetrixie1.30.4-1+deb13u3
mongo-c-driversource(unstable)2.5.1-1

Notes

[bookworm] - mongo-c-driver <postponed> (Minor issue)
https://jira.mongodb.org/browse/CDRIVER-6424

Search for package or bug name: Reporting problems