CVE-2026-106428
EUVD-2026-9514408.10.2026, 19:16
An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | c_driver | 1.1.0 ≤ 𝑥 < 1.30.13 | CNA |
| mongodb | c_driver | 2.0.0 ≤ 𝑥 < 2.4.0 | CNA |
Common Weakness Enumeration