Impact
A use‑after‑free bug resides in the reactive client‑side encryption component of the MongoDB Java Driver. When an encrypted operation is cancelled while native resources are still in use, those resources are freed prematurely, allowing the hosting application process to crash. The vulnerability requires an affected reactive encryption configuration that retrieves KMS credentials on demand and can be triggered by an attacker who can cause the operation to be cancelled.
Affected Systems
Vendors and products affected include MongoDB’s Java Driver. The issue is tied to the reactive client‑side encryption feature; no specific driver versions are listed in the CVE, so any release that implements the reactive encryption component and retrieves KMS credentials on demand is potentially vulnerable.
Risk and Exploitability
The CV high severity. Although no EPSS score is currently provided and the vulnerability is not listed in CISA’s KEV catalog, the risk is considerable because an attacker who can trigger a cancellation—through crafted requests or manipulated application logic—could cause the process to terminate. The attack vector is inferred to on how the driver is used. The lack of an exploit probability rating suggests that exploitation is plausible but unverified, so the focus should be on remediation rather than anticipation of widespread attacks.
OpenCVE Enrichment