{"id":"CVE-2026-96746","published":"2026-09-24T16:17:27.460","lastModified":"2026-09-24T21:04:40.340","description":"An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.12","tags":[]},{"url":"https://github.com/mongodb/mongo-c-driver/releases/tag/2.5.5","tags":[]},{"url":"https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46","tags":[]}],"exploitRefs":[{"url":"https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.12","tags":[]},{"url":"https://github.com/mongodb/mongo-c-driver/releases/tag/2.5.5","tags":[]},{"url":"https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46","tags":[]}],"hasPoc":true,"ai":null}