CVE-2026-9100
20.05.2026, 17:16
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | c_driver | 1.0 ≤ 𝑥 < 1.30.8 | CNA |
| mongodb | c_driver | 2.0 ≤ 𝑥 < 2.2.4 | CNA |
Debian Releases