← Voltar à pesquisa de CVEs

CVE-2026-81524

MongoDB C Driver

Descrição

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.

CVSS 5.4EPSS 0.156%Risco 0.55
Ver fonte
Publicação
2026-08-27 20:18:50
Versões afetadas
unknown
Tipo
Biblioteca
Última alteração
2026-08-28 00:18:20
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N