Security: mongodb/mongo-c-driver
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel streamGHSA-72hg-9rq2-f4xr published
Sep 18, 2026 by kevinAlbsHigh -
GridFS data disclosure and deletion via query-operator injection in file IDsGHSA-6v9c-36h3-hgmp published
Sep 11, 2026 by kevinAlbsModerate -
Heap buffer overflow via wrapped size check during SASL username canonicalizationGHSA-83f3-hpv5-58cq published
Sep 11, 2026 by kevinAlbsModerate -
Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C DriverGHSA-c9qr-rh56-vvrc published
Aug 27, 2026 by kevinAlbsModerate -
Heap overflow via truncated base64 encoding of binary fields in length-limited JSON outputGHSA-fqmh-x7gg-pfgw published
Sep 3, 2026 by kevinAlbsModerate -
Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS clientGHSA-fw3j-wh78-34mj published
Sep 3, 2026 by kevinAlbsHigh -
Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parserGHSA-8vwp-6h6c-hx6h published
Sep 3, 2026 by kevinAlbsModerate -
Heap write primitive via size round-up wrap during JSON parsing on 32-bit buildsGHSA-h2g7-2gxh-c5v2 published
Sep 3, 2026 by kevinAlbsModerate
Learn more about advisories related to mongodb/mongo-c-driver in the GitHub Advisory Database