CVE-2026-106428
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Oct 08, 2026
Vendor
unknown
Description
An out-of-bounds read in SCRAM authentication response parsing in the MongoDB C Driver can read one byte beyond a fixed-size buffer when processing a malformed server-final message. A server or network intermediary able to provide this message before server-signature verification can cause the application using the driver to terminate. The extra byte is not returned through the protocol.