Improper Input Handling in MongoDB Rust Driver's GridFS Component
CVE-2026-88024
6.1MEDIUM
What is CVE-2026-88024?
A vulnerability exists in the GridFS component of the MongoDB Rust Driver that allows an authenticated user to manipulate a caller-supplied structured file identifier. This manipulation can lead to the identifier being interpreted as a query condition rather than as a literal identifier. Consequently, an attacker may access stored file content beyond the intended target or trigger the removal of all GridFS file chunks within the affected bucket, rendering the stored file content unusable.
Affected Version(s)
Rust Driver 2.4.0 < 3.9.1