Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-6416 |
|
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it. | |
| Title | Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-10T18:29:53.256Z
Reserved: 2026-09-09T19:49:53.808Z
Link: CVE-2026-88035
Updated: 2026-09-10T18:29:45.428Z
Status : Awaiting Analysis
Published: 2026-09-10T19:17:40.953
Modified: 2026-09-10T19:44:21.980
Link: CVE-2026-88035
No data.
OpenCVE Enrichment
No data.
