Improper Validation of Specified Index, Position, or Offset in Input in MongoDB driver for C - CVE-2026-9100

 

Improper Validation of Specified Index, Position, or Offset in Input in MongoDB driver for C - CVE-2026-9100

Published: August 18, 2026


Vulnerability identifier: #VU144159
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9100
CWE-ID: CWE-1285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information or cause a denial of service.

The vulnerability exists due to improper validation of specified index, position, or offset in input in the legacy GridFS file reader API when processing malformed file metadata from GridFS collections. A remote user can supply crafted documents in a GridFS collection to disclose sensitive information or cause a denial of service.

The issue may result in a division-by-zero crash or an out-of-bounds read of process memory contents.


Affected software

MongoDB driver for C

How to mitigate CVE-2026-9100

Install security update from vendor's website.

MongoDB driver for C - addressed in versions 1.30.8, 2.2.4

External References

Related Security Bulletins