Incorrect Decimal Parsing in MongoDB C Driver
CVE-2026-106438
5.1MEDIUM
What is CVE-2026-106438?
A flaw in the MongoDB C Driver's Decimal128 string parsing allows it to accept improperly formatted decimal strings containing leading zeros. Rather than rejecting these inputs, the driver processes them incorrectly, leading to potential discrepancies in numeric values stored or utilized by applications. This vulnerability can be exploited by an actor who supplies a malicious decimal string, especially through Extended JSON parsing, impacting the integrity of data in applications relying on the C Driver.
Affected Version(s)
C Driver 1.4.0 < 1.30.13
C Driver 2.0.0 < 2.5.6