Description
An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
Published: 2026-10-08
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Data integrity compromise
Action: Update Driver
AI Analysis

Impact

An incorrect calculation in Decimal128 string parsing within the MongoDB C Driver can accept over‑precision inputs that contain leading zeros instead of rejecting them. This causes the driver to store or use a numeric value that does not match the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can therefore inject an incorrect value into the application’s data store or runtime logic.

Affected Systems

The vulnerability affects the MongoDB C Driver. No specific version range is listed in the advisory, so all releases of the driver that have not been updated to the fix for CDRIVER‑6419 are potentially affected.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score is not available. The attacker can exploit the flaw by supplying a crafted decimal string, for example through an API that accepts JSON or by embedding extended JSON in a data stream. The exploitation results in data corruption rather than remote code execution or denial of service, but can undermine application correctness and integrity.

Generated by OpenCVE AI on October 8, 2026 at 20:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MongoDB C Driver to a release that resolves CDRIVER‑6419.
  • Validate any user‑supplied Decimal128 strings to reject values that contain leading zeros or exceed the allowed precision before passing them to the driver.
  • If the application exposes Extended JSON parsing, limit its use to trusted data sources to reduce the attack surface.

Generated by OpenCVE AI on October 8, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
Title Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver
Weaknesses CWE-682
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:21:43.595Z

Reserved: 2026-10-06T16:40:40.579Z

Link: CVE-2026-106438

cve-icon Vulnrichment

Updated: 2026-10-08T19:20:44.186Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:59.703

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:11Z

Weaknesses