A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c Driver |
|
| Weaknesses | CWE-170 | |
| Vendors & Products |
Mongodb
Mongodb c Driver |
|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 17 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. | |
| Title | Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer | |
| Weaknesses | CWE-158 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-03-17T19:42:03.476Z
Reserved: 2026-03-17T19:11:07.170Z
Link: CVE-2026-4359
No data.
Status : Received
Published: 2026-03-17T20:16:15.233
Modified: 2026-03-17T20:16:15.233
Link: CVE-2026-4359
OpenCVE Enrichment
Updated: 2026-03-18T10:42:50Z