OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-96746 (CVSS 8.3)

NVD · officialPublished Sep 24, 2026Risk 37/100

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.

CVSS
8.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source