| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-93395 | vulnerable | vulnerable | fixed | fixed | A missing lower-bound validation in the bson_new_from_buffer() functio ... |
| CVE-2026-93394 | vulnerable | vulnerable | fixed | fixed | A flaw in libmongoc's SCRAM authentication implementation caused the c ... |
| CVE-2026-88036 | vulnerable | vulnerable (no DSA) | fixed | fixed | Improper neutralization of special elements in data query logic in the ... |
| CVE-2026-88035 | vulnerable | vulnerable (no DSA) | fixed | fixed | A size check in the client-side authentication path of the MongoDB C D ... |
| CVE-2026-84969 | fixed | vulnerable (no DSA) | fixed | fixed | A memory-handling error in the BSON-to-JSON conversion helpers of the ... |
| CVE-2026-84965 | vulnerable | vulnerable (no DSA) | fixed | fixed | An integer wraparound in an allocation size calculation in the BSON li ... |
| CVE-2026-84964 | vulnerable | vulnerable (no DSA) | fixed | fixed | A double free in the OpenSSL-based TLS certificate revocation checking ... |
| CVE-2026-84963 | vulnerable | vulnerable (no DSA) | fixed | fixed | An incorrect numeric conversion in the JSON parsing component of the M ... |
| CVE-2026-81524 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | A weakness in the MongoDB C Driver allows special elements in caller-s ... |
| Bug | Description |
|---|
| CVE-2026-9100 | The MongoDB C Driver's legacy GridFS API accepts malformed file metada ... |
| CVE-2026-6691 | The MongoDB C Driver's Cyrus SASL integration performs unsafe string c ... |
| CVE-2026-6231 | The bson_validate function may return early on specific inputs and inc ... |
| CVE-2026-4359 | A compromised third party cloud server or man-in-the-middle attacker c ... |
| CVE-2025-14911 | User-controlled chunkSize metadata from MongoDB lacks appropriate vali ... |
| CVE-2025-12119 | A mongoc_bulk_operation_t may read invalid memory if large options are ... |
| CVE-2025-0755 | The various bson_appendfunctions in the MongoDB C driver library may b ... |
| CVE-2024-6383 | The bson_string_append function in MongoDB C Driver may be vulnerable ... |
| CVE-2024-6381 | The bson_strfreev function in the MongoDB C driver library may be susc ... |
| CVE-2023-0437 | When calling bson_utf8_validateon some inputs a loop with an exit cond ... |
| CVE-2021-32050 | Some MongoDB Drivers may erroneously publish events containing authent ... |
| CVE-2018-16790 | _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in ... |