Impact
libmongocrypt suffers an integer underflow when parsing KMS endpoints, which leads to an allocation failure and causes the process to terminate. The fault does not read or write beyond its bounds, but the faulty allocation can crash the application. An attacker who can modify a key document in the key vault or supply a malformed KMS endpoint with a stray colon after the path or query can trigger this failure. The resulting loss of availability is confined to the affected process; no data is leaked or altered.
Affected Systems
MongoDB’s libmongocrypt library is affected. Specific version information is not listed, so all releases prior to the fix should be considered vulnerable until an updated package is available.
Risk and Exploitability
With a CVSS score of 7.1, this flaw is considered a high‑severity denial of service. EPSS data is not available, so the likelihood of exploitation cannot be quantified from public data. The vulnerability is not currently listed in CISA KEV. Attackers must be authenticated and able to feed a malicious KMS endpoint or alter a key record, which indicates that privilege escalation or compromised credentials could be prerequisite. If such conditions are met, the application is effectively knocked offline by a single payload.
OpenCVE Enrichment