Description
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Published: 2026-09-17
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution Potential
Action: Update Driver
AI Analysis

Impact

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. After the TLS handshake, a remote endpoint can send an oversized decrypted record that causes the driver to write beyond the bounds of a heap allocation. The flaw can lead to memory corruption, disclosure of adjacent heap contents, or crash of the client process. The impact is confined to the client process, but the lack of authentication or user interaction and the ability to trigger the bug remotely makes it a potential vector for remote code execution.

Affected Systems

The vulnerability affects MongoDB Inc.’s MongoDB C Driver when compiled for Windows with the Windows TLS backend. All Windows builds of the driver prior to the availability of a patch are vulnerable; specific version numbers are not listed in the advisory.

Risk and Exploitability

The CVSS score of 9.2 indicates high severity. The EPSS score of less than 1% shows a low but nonzero probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw can be triggered by any network participant without prior authentication, an exposed client could be compromised by an attacker able to observe or influence encrypted traffic. No authentication or user interaction is required to trigger the issue; the attack vector is purely remote network traffic entering the driver’s TLS processing.

Generated by OpenCVE AI on September 19, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest MongoDB C Driver release that resolves the TLS buffer overflow
  • If an upgrade is impractical, disable TLS or switch to a different TLS backend that does not rely on the vulnerable Windows implementation
  • Limit network exposure of the client by restricting inbound connections to trusted hosts or enforcing strict firewall rules

Generated by OpenCVE AI on September 19, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process. A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Title Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-18T17:35:11.797Z

Reserved: 2026-09-17T20:10:59.785Z

Link: CVE-2026-93393

cve-icon Vulnrichment

Updated: 2026-09-18T17:33:29.998Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:56.163

Modified: 2026-09-29T19:17:54.137

Link: CVE-2026-93393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:30:17Z

Weaknesses