Impact
An incorrect calculation in Decimal128 string parsing within the MongoDB C Driver can accept over‑precision inputs that contain leading zeros instead of rejecting them. This causes the driver to store or use a numeric value that does not match the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can therefore inject an incorrect value into the application’s data store or runtime logic.
Affected Systems
The vulnerability affects the MongoDB C Driver. No specific version range is listed in the advisory, so all releases of the driver that have not been updated to the fix for CDRIVER‑6419 are potentially affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score is not available. The attacker can exploit the flaw by supplying a crafted decimal string, for example through an API that accepts JSON or by embedding extended JSON in a data stream. The exploitation results in data corruption rather than remote code execution or denial of service, but can undermine application correctness and integrity.
OpenCVE Enrichment