PT-2026-108141 · Mongodb · Mongodb C Driver

CVE-2026-106438

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MongoDB C Driver (affected versions not specified)
Description An incorrect calculation in Decimal128 string parsing allows the driver to accept certain over-precision inputs containing leading zeros instead of rejecting them. This results in the production of a value that differs from the supplied text. An actor capable of providing a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106438

Affected Products

Mongodb C Driver