← Vulnerability feed

Vulnerability record · CVE-2021-32050 · published 29 August 2023

CVE-2021-32050: Mongodb c\+\+ information exposure vulnerability

Mongodb · C\+\+

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).

7.5 CVSS 3.1 High EPSS 0.65% · top 51.1% CWE-200 · Information exposureCWE-532 · Sensitive information in log file
7.5CVSS 3.1 base score
0.65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
13References
17 Jun 2026Last modified by NVD

Description

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32050 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-6691Mongodb c driver classic buffer overflow vulnerabilityThe MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before…EPSS 0.18%8.2CVE-2026-84964Mongodb c driver double free vulnerabilityA double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client …EPSS 0.26%7.8CVE-2024-7553Mongodb improper access control vulnerabilityIncorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win…EPSS 0.26%7.5CVE-2023-0437Mongodb c driver vulnerabilityWhen calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affe…EPSS 1.1%6.9CVE-2026-93395Mongodb c driver vulnerabilityA missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-…EPSS 0.40%6.9CVE-2026-84968Mongodb php driver out-of-bounds read vulnerabilityAn out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input…EPSS 0.33%6.9CVE-2025-12119Mongodb c driver vulnerabilityA mongoc_bulk_operation_t may read invalid memory if large options are passed.EPSS 0.20%6.3CVE-2026-93394Mongodb c driver vulnerabilityA flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof ev…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2021-32050), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.