PT-2026-108138 · Mongodb · Libmongocrypt

CVE-2026-106433

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libmongocrypt (affected versions not specified)
Description Improper state management occurs when cleaning up a key document that contains duplicate masterKey fields, causing provider-specific data to be treated as an incompatible type. An authenticated actor with permissions to modify key vault documents, or a server returning such a document, can trigger invalid memory access and invalid frees within the client process. This may lead to application termination or corruption of process memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106433

Affected Products

Libmongocrypt