MEDIUMVulnerability

CVE-2026-84966

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate the calling process. No authentication is required, but the calling application must pass the oversized name in a specific form.

Properties

severity
MEDIUM
score
5.1
cve_id
CVE-2026-84966
signal_observed_at
2026-09-23T04:35:08+00:00
vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-03T16:18:25.563
last_modified
2026-09-22T15:54:16.740

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Incorrect Conversion between Numeric Types

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84966 — Ninja Signal Threat Intelligence | Ninja Signal