Out-of-Bounds Read Vulnerability in MongoDB C Driver
CVE-2026-106428

6.3MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-106428?

An out-of-bounds read occurs within the SCRAM authentication response parsing of the MongoDB C Driver. This issue can be triggered when a malformed server-final message is processed, potentially allowing an attacker with access to the server or a network intermediary to read one byte beyond a defined buffer. This flaw may lead to unexpected behavior or termination of the application utilizing the driver, as the additional byte is not communicated back via the network protocol, posing a risk to application stability.

Affected Version(s)

C Driver 1.1.0 < 1.30.13

C Driver 2.0.0 < 2.4.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.