Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-106428

LOW NVD
CVSS Score 3.7
Severity LOW
Published Oct 08, 2026
Vendor unknown

Description

An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.

References