Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92756 1 Mongodb 1 Mongodb Entity Framework Core Provider 2026-09-18 5.5 Medium
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
CVE-2026-92758 1 Mongodb 1 Mongodb Entity Framework Core Provider 2026-09-18 5.5 Medium
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
CVE-2026-92757 1 Mongodb 1 Mongodb Entity Framework Core Provider 2026-09-18 5.5 Medium
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.