CVE-2026-93393
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-787
Escritura fuera de límites
Fecha de publicación:
17/09/2026
Última modificación:
29/09/2026
Descripción
*** Pendiente de traducción *** A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
Impacto
Puntuación base 4.0
9.20
Gravedad 4.0
CRÍTICA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:* | 1.10.0 (incluyendo) | 1.30.11 (excluyendo) |
| cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:* | 2.2.0 (incluyendo) | 2.5.4 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página


