MEDIUMVulnerability

CVE-2026-84964

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the trusted endpoint may cause the connecting client application to terminate unexpectedly.

Properties

severity
MEDIUM
score
5.9
cve_id
CVE-2026-84964
signal_observed_at
2026-09-23T04:35:08+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-03T16:18:25.270
last_modified
2026-09-22T16:19:25.187

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Double Free

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84964 — Ninja Signal Threat Intelligence | Ninja Signal