← Vulnerability feed

Vulnerability record · CVE-2026-84963 · published 3 September 2026

CVE-2026-84963: Mongodb c driver vulnerability

Mongodb · C Driver

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.

6.3 CVSS 4.0 Medium EPSS 0.31% · top 78.6% CWE-681 · CWE-681
6.3CVSS 4.0 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-84963 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-6691Mongodb c driver classic buffer overflow vulnerabilityThe MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before…EPSS 0.18%8.2CVE-2026-84964Mongodb c driver double free vulnerabilityA double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client …EPSS 0.26%7.8CVE-2024-7553Mongodb improper access control vulnerabilityIncorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win…EPSS 0.26%7.5CVE-2023-0437Mongodb c driver vulnerabilityWhen calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affe…EPSS 1.1%7.5CVE-2021-32050Mongodb c\+\+ information exposure vulnerabilitySome MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu…EPSS 0.65%6.9CVE-2026-93395Mongodb c driver vulnerabilityA missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-…EPSS 0.40%6.9CVE-2025-12119Mongodb c driver vulnerabilityA mongoc_bulk_operation_t may read invalid memory if large options are passed.EPSS 0.20%6.3CVE-2026-93394Mongodb c driver vulnerabilityA flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof ev…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2026-84963), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.