SecBoard
Zurück zur CVE-Übersicht

CVE-2026-84965

MEDIUM(5.1)

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Risk Signal Score13/100 — NIEDRIG
  • CVSS 5.1 — Mittel

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

5.1

Technische Schwere

Beschreibung

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service.

Betroffene Produkte

  • cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*
  • cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Referenzen