[Git][security-tracker-team/security-tracker][master] Add new mongodb driver related CVEs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 09:17:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cf21ac7d by Salvatore Bonaccorso at 2026-09-04T10:16:49+02:00
Add new mongodb driver related CVEs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -548,25 +548,37 @@ CVE-2026-85012 (Improper neutralization of special elements used in an OS comman
CVE-2026-84989 (ntopng is a web-based network traffic monitoring application. In versi ...)
- ntopng <removed>
CVE-2026-84971 (Improper handling of an unexpected value size in the decryption path o ...)
- TODO: check
+ - libmongocrypt 1.20.4-1
+ NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-971
CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing component of ...)
- TODO: check
+ - mongo-cxx-driver 4.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CXX-3547
CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the ...)
- TODO: check
+ - mongo-c-driver 2.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
TODO: check
CVE-2026-84967 (A component of the MongoDB extension for Visual Studio Code does not n ...)
TODO: check
CVE-2026-84966 (An incorrect numeric type conversion in the BSON document building com ...)
- TODO: check
+ - mongo-cxx-driver 4.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CXX-3548
CVE-2026-84965 (An integer wraparound in an allocation size calculation in the BSON li ...)
- TODO: check
+ - mongo-c-driver 2.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6405
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/8a4c4416a171b66a3eb0b136f844c62ca9e36025 (2.5.2)
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/aba72444f8e8950b8a57636b1ad72a5a853f8264 (1.30.9)
CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation checking ...)
- TODO: check
+ - mongo-c-driver 2.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6409
CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of the M ...)
- TODO: check
+ - mongo-c-driver 2.5.2-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
- TODO: check
+ - libmongocrypt 1.20.2-1
+ NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-960
CVE-2026-84888 (A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Th ...)
NOT-FOR-US: RightNow-AI OpenFang
CVE-2026-84887 (A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affe ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf21ac7d276ca661b11793b8f13d537bc0c87dc9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf21ac7d276ca661b11793b8f13d537bc0c87dc9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/3776e541/attachment.htm>
More information about the debian-security-tracker-commits
mailing list