Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-6410 |
|
Thu, 03 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c Driver |
|
| Vendors & Products |
Mongodb
Mongodb c Driver |
Thu, 03 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the application that links the driver, may cause a small amount of data outside the intended buffer to be altered. | |
| Title | Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-03T15:08:11.873Z
Reserved: 2026-09-02T17:58:52.742Z
Link: CVE-2026-84969
Updated: 2026-09-03T15:08:05.082Z
Status : Received
Published: 2026-09-03T15:17:36.250
Modified: 2026-09-03T16:18:25.857
Link: CVE-2026-84969
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:45:06Z
-
CWE-787
Out-of-bounds Write