CVE-2026-106438
EUVD-2026-9515408.10.2026, 19:16
An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | c_driver | 1.4.0 ≤ 𝑥 < 1.30.13 | CNA |
| mongodb | c_driver | 2.0.0 ≤ 𝑥 < 2.5.6 | CNA |
Common Weakness Enumeration