CVE-2026-106428

EUVD-2026-95144
An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mongodbCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mongodbc_driver
1.1.0 ≤
𝑥
< 1.30.13
CNA
mongodbc_driver
2.0.0 ≤
𝑥
< 2.4.0
CNA