Integer Underflow in MongoDB's Key Management System
CVE-2026-106429
7.1HIGH
What is CVE-2026-106429?
An integer underflow vulnerability exists in the KMS endpoint-parsing logic of MongoDB's libmongocrypt. This issue can lead to an allocation failure, resulting in abrupt termination of the application process. It could occur when an authenticated user modifies a key document within the key vault collection or when an application improperly accepts a KMS endpoint that includes a colon after the path or query during key creation, without accessing memory outside its allocated bounds.
Affected Version(s)
libmongocrypt 1.1.0 < 1.20.5