Vulnerability Details CVE-2026-84969
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the application that links the driver, may cause a small amount of data outside the intended buffer to be altered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.2%
CVSS Severity
CVSS v3 Score 3.7
Products affected by CVE-2026-84969
-
cpe:2.3:a:mongodb:c_driver:1.30.0
-
cpe:2.3:a:mongodb:c_driver:1.30.1
-
cpe:2.3:a:mongodb:c_driver:1.30.2
-
cpe:2.3:a:mongodb:c_driver:1.30.3
-
cpe:2.3:a:mongodb:c_driver:1.30.4
-
cpe:2.3:a:mongodb:c_driver:1.30.5
-
cpe:2.3:a:mongodb:c_driver:1.30.6
-
cpe:2.3:a:mongodb:c_driver:1.30.7
-
cpe:2.3:a:mongodb:c_driver:1.30.8
-
cpe:2.3:a:mongodb:c_driver:2.0.0
-
cpe:2.3:a:mongodb:c_driver:2.0.1
-
cpe:2.3:a:mongodb:c_driver:2.0.2
-
cpe:2.3:a:mongodb:c_driver:2.1.0
-
cpe:2.3:a:mongodb:c_driver:2.1.1
-
cpe:2.3:a:mongodb:c_driver:2.1.2
-
cpe:2.3:a:mongodb:c_driver:2.2.0
-
cpe:2.3:a:mongodb:c_driver:2.2.1
-
cpe:2.3:a:mongodb:c_driver:2.2.2
-
cpe:2.3:a:mongodb:c_driver:2.2.3
-
cpe:2.3:a:mongodb:c_driver:2.2.4
-
cpe:2.3:a:mongodb:c_driver:2.3.0
-
cpe:2.3:a:mongodb:c_driver:2.3.1
-
cpe:2.3:a:mongodb:c_driver:2.3.2
-
cpe:2.3:a:mongodb:c_driver:2.3.3
-
cpe:2.3:a:mongodb:c_driver:2.4.0
-
cpe:2.3:a:mongodb:c_driver:2.5.0
-
cpe:2.3:a:mongodb:c_driver:2.5.1