CVE-2026-106429
EUVD-2026-9516008.10.2026, 19:16
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | libmongocrypt | 1.1.0 ≤ 𝑥 < 1.20.5 | CNA |
Common Weakness Enumeration