PT-2026-85068 · Mongodb · Mongodb C Driver

CVE-2026-84964

·

Published

2026-09-03

·

Updated

2026-09-07

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MongoDB C Driver (affected versions not specified)
Description A double free occurs in the OpenSSL-based TLS certificate revocation checking path. This issue is triggered during the handshake process when a TLS endpoint trusted by the client sends specially formed certificate data, causing the same heap object to be released twice. An unauthenticated party acting as the trusted endpoint can exploit this to cause the connecting client application to terminate unexpectedly. A double free is a memory corruption issue where the program attempts to free the same memory address twice, often leading to crashes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84964
OPENSUSE-SU-2026:11706-1

Affected Products

Mongodb C Driver