CVE-2026-9100
EUVD-2026-3113220.05.2026, 17:16
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mongodb | c_driver | 1.10.0 ≤ 𝑥 < 1.30.8 |
| mongodb | c_driver | 2.0.0 ≤ 𝑥 < 2.2.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases