Impact
An improper state management bug in MongoDB libmongocrypt allows provider-specific data to be processed as an incompatible type during the cleanup of a key document that contains duplicate masterKey fields. The flaw can lead to invalid memory access and invalid frees in the client process. When triggered, it can terminate the application or corrupt process memory, potentially compromising the confidentiality, integrity, or availability of the affected system. This weakness is cataloged as CWE-843.
Affected Systems
MongoDB’s libmongocrypt library is affected. The vulnerability can be exploited by any authenticated actor who can modify key‑vault documents or by a server that returns a key document with duplicate masterKey fields. The specific version ranges impacted were not disclosed in the available data.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS score is currently available, so the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of assessment. Based on the description, the likely attack vector requires either an authenticated user with write access to key‑vault documents or a compromised server capable of returning malformed key documents. A successful exploit will cause a crash or memory corruption in a client process that interacts with libmongocrypt.
OpenCVE Enrichment