Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-6281 |
|
Wed, 20 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb c Driver |
|
| Vendors & Products |
Mongodb
Mongodb c Driver |
Wed, 20 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process memory contents (via an out-of-bounds read). | |
| Title | Heap memory out of bounds read and crash in C Driver legacy GridFS file reader | |
| Weaknesses | CWE-1285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-05-20T17:20:32.902Z
Reserved: 2026-05-20T15:13:47.129Z
Link: CVE-2026-9100
Updated: 2026-05-20T17:20:29.521Z
Status : Awaiting Analysis
Published: 2026-05-20T17:16:32.360
Modified: 2026-06-17T11:04:50.210
Link: CVE-2026-9100
No data.
OpenCVE Enrichment
Updated: 2026-05-20T18:00:14Z