CVE-2026-88032

NameCVE-2026-88032
DescriptionA use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1147406

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-java-driver (PTS)bookworm, trixie3.6.3-2vulnerable
forky, sid3.6.3-2.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-java-driversource(unstable)(unfixed)1147406

Notes

[trixie] - mongo-java-driver <no-dsa> (Minor issue)
[bookworm] - mongo-java-driver <postponed> (Minor issue, DoS)
https://jira.mongodb.org/browse/JAVA-6276
https://github.com/mongodb/mongo-java-driver/security/advisories/GHSA-c4c8-c376-3p6c

Search for package or bug name: Reporting problems