Incorrect Decimal Parsing in MongoDB C Driver
CVE-2026-106438

5.1MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-106438?

A flaw in the MongoDB C Driver's Decimal128 string parsing allows it to accept improperly formatted decimal strings containing leading zeros. Rather than rejecting these inputs, the driver processes them incorrectly, leading to potential discrepancies in numeric values stored or utilized by applications. This vulnerability can be exploited by an actor who supplies a malicious decimal string, especially through Extended JSON parsing, impacting the integrity of data in applications relying on the C Driver.

Affected Version(s)

C Driver 1.4.0 < 1.30.13

C Driver 2.0.0 < 2.5.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.