Description
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Application Termination or Memory Corruption
Action: Apply Patch
AI Analysis

Impact

An improper state management bug in MongoDB libmongocrypt allows provider-specific data to be processed as an incompatible type during the cleanup of a key document that contains duplicate masterKey fields. The flaw can lead to invalid memory access and invalid frees in the client process. When triggered, it can terminate the application or corrupt process memory, potentially compromising the confidentiality, integrity, or availability of the affected system. This weakness is cataloged as CWE-843.

Affected Systems

MongoDB’s libmongocrypt library is affected. The vulnerability can be exploited by any authenticated actor who can modify key‑vault documents or by a server that returns a key document with duplicate masterKey fields. The specific version ranges impacted were not disclosed in the available data.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. No EPSS score is currently available, so the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of assessment. Based on the description, the likely attack vector requires either an authenticated user with write access to key‑vault documents or a compromised server capable of returning malformed key documents. A successful exploit will cause a crash or memory corruption in a client process that interacts with libmongocrypt.

Generated by OpenCVE AI on October 8, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest version of MongoDB libmongocrypt where the duplicate masterKey handling bug is fixed
  • Validate that all key‑vault documents conform to the expected schema and do not contain duplicate masterKey fields
  • Implement or enforce strict input validation on any external source that can supply key‑vault documents to prevent malformed data from reaching the client

Generated by OpenCVE AI on October 8, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb libmongocrypt
Vendors & Products Mongodb
Mongodb libmongocrypt

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.
Title Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Libmongocrypt
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:30:26.703Z

Reserved: 2026-10-06T16:40:35.016Z

Link: CVE-2026-106433

cve-icon Vulnrichment

Updated: 2026-10-08T19:30:22.387Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:59.233

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')