Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-96746

MongoDB C driver connection-monitor overflow

The MongoDB C driver can write past a heap buffer when an attacker controls name resolution for hosts in the connection string. The published result is a crash. Fixed in 1.30.12 and 2.5.5. CVSS 4.0 score 8.3.

CVSS
8.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Class
DoS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
MongoDB
Products
MongoDB C Driver
Affected
C Driver releases before 1.30.12 on the 1.x line and before 2.5.5 on the 2.x line. The attacker must control name resolution and the responses of the named hosts.
Fixed
1.30.12 and 2.5.5
Published
24 Sept 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-96746 is an out-of-bounds write in the connection-monitoring logic of the MongoDB C driver. NVD says an unauthenticated party who controls name resolution, and the responses of the hosts named in the client’s connection string, may write past the end of a heap buffer. The result NVD states is that the application can terminate. The CVSS 4.0 score is 8.3. Availability is high. Confidentiality on the vulnerable system is none. There is an attack requirement. CWE-787.

NVD’s references point at C driver 1.30.12 and 2.5.5 as the fixed tags. CISA has not listed the CVE. The description does not establish code execution. This is not CVE-2026-96748.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-96746