Description
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.
Published: 2026-09-10
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow
Action: Assess Impact
AI Analysis

Impact

An oversized SASL username value can bypass a size check in the C Driver and be copied past the end of a small buffer, causing the application that uses the driver to crash. This vulnerability does not provide remote code execution or privilege escalation, but it can disrupt the service by terminating the application. The weakness is a classic integer overflow or signed/unsigned mismatch, identified as CWE-190.

Affected Systems

The MongoDB C Driver is affected. The issue arises only in builds that include the optional external SASL authentication backend and when a connection is configured to use that backend. No specific version numbers are supplied in the advisory.

Risk and Exploitability

The severity is a moderate CVSS score of 5.7. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker who can influence the driver's connection configuration on a system that hosts the driver; this may imply remote code supplied by an application that initializes the driver, or local compromise. The likelihood of exploitation is low to moderate because the vulnerable code path is conditional on the optional SASL backend being present and enabled, but any application using that feature must consider the risk of denial of service.

Generated by OpenCVE AI on September 10, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a release of the MongoDB C Driver that includes the fix for CDRIVER-6416.
  • Disabling or removing the optional external SASL authentication backend to eliminate the vulnerable code path.
  • Implement application-level validation to enforce an appropriate username length before passing it to the driver.

Generated by OpenCVE AI on September 10, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds the driver to terminate unexpectedly. Reaching this code requires a build in which the optional external SASL authentication backend is present and a connection configured to use it.
Title Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:29:53.256Z

Reserved: 2026-09-09T19:49:53.808Z

Link: CVE-2026-88035

cve-icon Vulnrichment

Updated: 2026-09-10T18:29:45.428Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T19:17:40.953

Modified: 2026-09-16T18:08:46.303

Link: CVE-2026-88035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:15:15Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound