216.73.216.233

CVE-2026-9100

· Published 20/05/2026 17:16 · Modified 20/05/2026 17:32

Labels: CVE-2026-9100 2026-05-20CVE-2026-9100CWE-1285[email protected]

Essential information

Published
20/05/2026 17:16
Modified
20/05/2026 17:32
Author
Creator
CVSS
6.0 MEDIUM (v3) 6.0 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongodb c driver cpe:2.3:a:mongodb:mongodb_c_driver:*:*:*:*:*:*:*:*

References