libmongocrypt vulnerability

Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.

Published 3 Sep 2026Updated 17 Sep 20261 sources
CVSS 7.1

Source timeline

CVE record published by NVDView source ↗