Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/MONGOCRYPT-971 |
|
Thu, 03 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running. | |
| Title | Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-03T15:10:21.808Z
Reserved: 2026-09-02T17:58:52.743Z
Link: CVE-2026-84971
Updated: 2026-09-03T15:10:16.072Z
Status : Received
Published: 2026-09-03T15:17:36.547
Modified: 2026-09-03T16:18:26.083
Link: CVE-2026-84971
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:45:06Z
-
CWE-617
Reachable Assertion