Use-After-Free Vulnerability in MongoDB Java Driver
CVE-2026-88032
8.2HIGH
What is CVE-2026-88032?
A use-after-free vulnerability exists in the reactive client-side encryption component of the MongoDB Java Driver, which can lead to the premature freeing of native resources. This occurs when an encrypted operation is still in progress, but is subsequently cancelled, enabling malintent from a third party to potentially terminate the hosting application process. This issue necessitates a specific reactive encryption configuration that retrieves Key Management Service (KMS) credentials on-demand, further complicating security for implementations relying on this functionality.
Affected Version(s)
Java Driver 4.2.0 < 5.11.1