[Git][security-tracker-team/security-tracker][master] Add new MongoDB driver issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 04:50:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e524e8bf by Salvatore Bonaccorso at 2026-09-11T05:50:06+02:00
Add new MongoDB driver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -256,21 +256,37 @@ CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookie
 	NOTE: https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
 	NOTE: Fixed by: https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c (v0.9.2)
 CVE-2026-88036 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- mongo-c-driver 2.5.3-1
+	NOTE: https://jira.mongodb.org/browse/CDRIVER-6427
+	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6b50646296da30aa7ef155feb5f238e59328730e (2.5.3)
+	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6197ab3d7a24f3323a2cf297aae81c7cec96264b (1.3.10)
 CVE-2026-88035 (A size check in the client-side authentication path of the MongoDB C D ...)
-	TODO: check
+	- mongo-c-driver 2.5.3-1
+	NOTE: https://jira.mongodb.org/browse/CDRIVER-6416
+	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/ddfe9e5fe9e3e43ce8f3b1429cacc872767ee2ba (2.5.3)
+	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01245bbd8888946ec54c8faadcb5f40670592d26 (1.3.10)
 CVE-2026-88034 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- mongo-cxx-driver 4.5.3-1
+	NOTE: https://jira.mongodb.org/browse/CXX-3556
+	NOTE: Fixed by: https://github.com/mongodb/mongo-cxx-driver/commit/5e52e715bf820d2d4efff01b8520eb8640c98b29 (r4.5.3)
 CVE-2026-88033 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- mongo-java-driver <unfixed>
+	NOTE: https://jira.mongodb.org/browse/JAVA-6283
 CVE-2026-88032 (A use-after-free in the reactive client-side encryption component of t ...)
-	TODO: check
+	- mongo-java-driver <unfixed>
+	NOTE: https://jira.mongodb.org/browse/JAVA-6276
 CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- golang-mongodb-mongo-driver <unfixed>
+	NOTE: https://jira.mongodb.org/browse/GODRIVER-4081
+	NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96 (v1.17.10)
 CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- ruby-mongo <unfixed>
+	NOTE: https://jira.mongodb.org/browse/RUBY-3941
+	NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
 CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
-	TODO: check
+	- pymongo <unfixed>
+	NOTE: https://jira.mongodb.org/browse/PYTHON-5994
+	NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
 CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
 	NOT-FOR-US: MongoDB integration for Laravel
 CVE-2026-88027 (Improper neutralization of special elements in data query logic in the ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e524e8bf919cdfd5db7e261bd55b834e1db9e8b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e524e8bf919cdfd5db7e261bd55b834e1db9e8b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/7b9266a2/attachment.htm>


More information about the debian-security-tracker-commits mailing list