[Git][security-tracker-team/security-tracker][master] Add new MongoDB driver issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 11 04:50:36 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e524e8bf by Salvatore Bonaccorso at 2026-09-11T05:50:06+02:00
Add new MongoDB driver issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -256,21 +256,37 @@ CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookie
NOTE: https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
NOTE: Fixed by: https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c (v0.9.2)
CVE-2026-88036 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - mongo-c-driver 2.5.3-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6427
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6b50646296da30aa7ef155feb5f238e59328730e (2.5.3)
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6197ab3d7a24f3323a2cf297aae81c7cec96264b (1.3.10)
CVE-2026-88035 (A size check in the client-side authentication path of the MongoDB C D ...)
- TODO: check
+ - mongo-c-driver 2.5.3-1
+ NOTE: https://jira.mongodb.org/browse/CDRIVER-6416
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/ddfe9e5fe9e3e43ce8f3b1429cacc872767ee2ba (2.5.3)
+ NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01245bbd8888946ec54c8faadcb5f40670592d26 (1.3.10)
CVE-2026-88034 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - mongo-cxx-driver 4.5.3-1
+ NOTE: https://jira.mongodb.org/browse/CXX-3556
+ NOTE: Fixed by: https://github.com/mongodb/mongo-cxx-driver/commit/5e52e715bf820d2d4efff01b8520eb8640c98b29 (r4.5.3)
CVE-2026-88033 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - mongo-java-driver <unfixed>
+ NOTE: https://jira.mongodb.org/browse/JAVA-6283
CVE-2026-88032 (A use-after-free in the reactive client-side encryption component of t ...)
- TODO: check
+ - mongo-java-driver <unfixed>
+ NOTE: https://jira.mongodb.org/browse/JAVA-6276
CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - golang-mongodb-mongo-driver <unfixed>
+ NOTE: https://jira.mongodb.org/browse/GODRIVER-4081
+ NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96 (v1.17.10)
CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - ruby-mongo <unfixed>
+ NOTE: https://jira.mongodb.org/browse/RUBY-3941
+ NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
- TODO: check
+ - pymongo <unfixed>
+ NOTE: https://jira.mongodb.org/browse/PYTHON-5994
+ NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
NOT-FOR-US: MongoDB integration for Laravel
CVE-2026-88027 (Improper neutralization of special elements in data query logic in the ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e524e8bf919cdfd5db7e261bd55b834e1db9e8b0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e524e8bf919cdfd5db7e261bd55b834e1db9e8b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/7b9266a2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list