CVE-2026-88035

NameCVE-2026-88035
DescriptionA size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-c-driver (PTS)bookworm1.23.1-1+deb12u3vulnerable
trixie1.30.4-1+deb13u2vulnerable
forky2.5.2-1vulnerable
sid2.5.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-c-driversource(unstable)2.5.3-1

Notes

https://jira.mongodb.org/browse/CDRIVER-6416
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/ddfe9e5fe9e3e43ce8f3b1429cacc872767ee2ba (2.5.3)
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01245bbd8888946ec54c8faadcb5f40670592d26 (1.3.10)

Search for package or bug name: Reporting problems