LOWVulnerability

CVE-2026-84969

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the application that links the driver, may cause a small amount of data outside the intended buffer to be altered.

Properties

severity
LOW
score
3.7
epss_score
0.00166
cve_id
CVE-2026-84969
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-03T15:17:36.250
last_modified
2026-09-10T19:50:25.773
epss_percentile
0.06147

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Write

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84969 — Ninja Signal Threat Intelligence | Ninja Signal