Beveiligingsadvies

CVE-2026-9100

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-20 15:55:13
Laatst bijgewerkt 2026-05-20 17:20:32
Toegewezen door mongodb
CVSS-score 6.0
Status PUBLISHED

Beschrijving

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read).