CVE-2026-96746
MongoDB C driver connection-monitor overflow
The MongoDB C driver can write past a heap buffer when an attacker controls name resolution for hosts in the connection string. The published result is a crash. Fixed in 1.30.12 and 2.5.5. CVSS 4.0 score 8.3.
- CVSS
- 8.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
- Class
- DoS
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- MongoDB
- Products
- MongoDB C Driver
- Affected
- C Driver releases before 1.30.12 on the 1.x line and before 2.5.5 on the 2.x line. The attacker must control name resolution and the responses of the named hosts.
- Fixed
- 1.30.12 and 2.5.5
- CWE
- CWE-787
- Published
- 24 Sept 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-96746 is an out-of-bounds write in the connection-monitoring logic of the MongoDB C driver. NVD says an unauthenticated party who controls name resolution, and the responses of the hosts named in the client’s connection string, may write past the end of a heap buffer. The result NVD states is that the application can terminate. The CVSS 4.0 score is 8.3. Availability is high. Confidentiality on the vulnerable system is none. There is an attack requirement. CWE-787.
NVD’s references point at C driver 1.30.12 and 2.5.5 as the fixed tags. CISA has not listed the CVE. The description does not establish code execution. This is not CVE-2026-96748.