Description
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

libmongocrypt suffers an integer underflow when parsing KMS endpoints, which leads to an allocation failure and causes the process to terminate. The fault does not read or write beyond its bounds, but the faulty allocation can crash the application. An attacker who can modify a key document in the key vault or supply a malformed KMS endpoint with a stray colon after the path or query can trigger this failure. The resulting loss of availability is confined to the affected process; no data is leaked or altered.

Affected Systems

MongoDB’s libmongocrypt library is affected. Specific version information is not listed, so all releases prior to the fix should be considered vulnerable until an updated package is available.

Risk and Exploitability

With a CVSS score of 7.1, this flaw is considered a high‑severity denial of service. EPSS data is not available, so the likelihood of exploitation cannot be quantified from public data. The vulnerability is not currently listed in CISA KEV. Attackers must be authenticated and able to feed a malicious KMS endpoint or alter a key record, which indicates that privilege escalation or compromised credentials could be prerequisite. If such conditions are met, the application is effectively knocked offline by a single payload.

Generated by OpenCVE AI on October 8, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libmongocrypt to a patched release that corrects the integer underflow in KMS endpoint parsing.
  • Sanitize KMS endpoint strings in application code to reject colons appearing after the path or query part unless explicitly required by the protocol.
  • Enforce strict access controls on key vault collections to limit the ability of users to modify key documents.

Generated by OpenCVE AI on October 8, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb libmongocrypt
Vendors & Products Mongodb
Mongodb libmongocrypt

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.
Title Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Libmongocrypt
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:30:01.396Z

Reserved: 2026-10-06T16:40:35.016Z

Link: CVE-2026-106429

cve-icon Vulnrichment

Updated: 2026-10-08T19:29:58.023Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:58.750

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)