Out-of-Bounds Read Vulnerability in MongoDB C Driver
CVE-2026-106428
6.3MEDIUM
What is CVE-2026-106428?
An out-of-bounds read occurs within the SCRAM authentication response parsing of the MongoDB C Driver. This issue can be triggered when a malformed server-final message is processed, potentially allowing an attacker with access to the server or a network intermediary to read one byte beyond a defined buffer. This flaw may lead to unexpected behavior or termination of the application utilizing the driver, as the additional byte is not communicated back via the network protocol, posing a risk to application stability.
Affected Version(s)
C Driver 1.1.0 < 1.30.13
C Driver 2.0.0 < 2.4.0