Information on source package mongo-c-driver

Available versions

ReleaseVersion
bullseye1.17.6-1
bullseye (security)1.17.6-1+deb11u2
bookworm1.23.1-1+deb12u3
trixie1.30.4-1+deb13u2
forky2.3.0-1
sid2.3.0-1

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-9100vulnerablefixedfixedfixedfixedThe MongoDB C Driver's legacy GridFS API accepts malformed file metada ...
CVE-2026-6691vulnerable (no DSA, postponed)fixedfixedfixedfixedThe MongoDB C Driver's Cyrus SASL integration performs unsafe string c ...
CVE-2026-6231vulnerable (no DSA, postponed)fixedfixedfixedfixedThe bson_validate function may return early on specific inputs and inc ...
CVE-2026-4359vulnerable (no DSA, postponed)fixedfixedfixedfixedA compromised third party cloud server or man-in-the-middle attacker c ...
CVE-2025-14911vulnerable (no DSA, postponed)fixedfixedfixedfixedUser-controlled chunkSize metadata from MongoDB lacks appropriate vali ...

Resolved issues

BugDescription
CVE-2025-12119A mongoc_bulk_operation_t may read invalid memory if large options are ...
CVE-2025-0755The various bson_appendfunctions in the MongoDB C driver library may b ...
CVE-2024-6383The bson_string_append function in MongoDB C Driver may be vulnerable ...
CVE-2024-6381The bson_strfreev function in the MongoDB C driver library may be susc ...
CVE-2023-0437When calling bson_utf8_validateon some inputs a loop with an exit cond ...
CVE-2021-32050Some MongoDB Drivers may erroneously publish events containing authent ...
CVE-2018-16790_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in ...

Security announcements

DSA / DLADescription
DLA-4438-1mongo-c-driver - security update
DLA-4175-1mongo-c-driver - security update

Search for package or bug name: Reporting problems