CVE-2026-93393
EUVD-2026-8243517.09.2026, 21:17
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | c_driver | 2.4.0 | CNA |
| mongodb | c_driver | 2.3.0 ≤ 𝑥 ≤ 2.3.3 | CNA |
| mongodb | c_driver | 2.2.0 ≤ 𝑥 ≤ 2.2.4 | CNA |
| mongodb | c_driver | 2.1.0 ≤ 𝑥 ≤ 2.1.2 | CNA |
| mongodb | c_driver | 2.0.0 ≤ 𝑥 ≤ 2.0.2 | CNA |
| mongodb | c_driver | 1.30.0 ≤ 𝑥 ≤ 1.30.8 | CNA |
| mongodb | c_driver | 1.29.0 ≤ 𝑥 ≤ 1.29.2 | CNA |
| mongodb | c_driver | 1.28.0 ≤ 𝑥 ≤ 1.28.1 | CNA |
| mongodb | c_driver | 1.27.0 ≤ 𝑥 ≤ 1.27.6 | CNA |
| mongodb | c_driver | 1.26.0 ≤ 𝑥 ≤ 1.26.2 | CNA |
| mongodb | c_driver | 1.25.0 ≤ 𝑥 ≤ 1.25.4 | CNA |
| mongodb | c_driver | 1.24.0 ≤ 𝑥 ≤ 1.24.4 | CNA |
Common Weakness Enumeration