CVE Watchtower

← Back to CVE List

CVE-2026-93393NVD

Description

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Severity Level
HIGH (8.1)
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.28% (percentile 20.8%)

CVSS Base Metrics

CVSS v3 (3.1)
HIGH 8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 (4.0)
CRITICAL 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Weaknesses (CWE)

CWE-787 - CWE-787: Out-of-bounds Write

Affected & Patched Versions

ProductAffected VersionsPatched Version
MongoDB Inc. C Driver2.4.0, 2.3.0 - <= 2.3.3, 2.2.0 - <= 2.2.4, 2.1.0 - <= 2.1.2, 2.0.0 - <= 2.0.2, 1.30.0 - <= 1.30.8, 1.29.0 - <= 1.29.2, 1.28.0 - <= 1.28.1, 1.27.0 - <= 1.27.6, 1.26.0 - <= 1.26.2, 1.25.0 - <= 1.25.4, 1.24.0 - <= 1.24.4N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.