Junglewise Threat Intelligence

CVE-2026-81529: MongoDB C# Driver connection-option injection in URL builder

CVE-2026-81529 · Severity: high · CVSS 7.1 · Published 2026-08-27

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C# Driver contains a flaw in how it constructs database connection strings. When an application incorporates untrusted user input into connection settings and then re-parses them, the driver fails to properly escape special characters, allowing an attacker to inject or suppress security-relevant connection options. This could enable an attacker to bypass authentication requirements, disable encryption, or modify database access behavior.

Technical details

The vulnerability is a URL encoding/injection flaw in the MongoUrlBuilder.ToString() method. The method concatenates user-controlled string values directly into a MongoDB connection URL without percent-encoding reserved characters ('?', '&', ','), allowing an attacker to inject additional connection options or modify existing ones. When the malformed URL is re-parsed via ToMongoUrl(), the injected delimiters are interpreted as authoritative connection parameters. The attack requires application code that accepts untrusted input, passes it to the URL builder, and then re-parses the result. The fix (implemented in version 3.11.1) ensures all string-valued settings are properly percent-encoded, mirroring the behavior of ConnectionString.BuildResolvedConnectionString.

Affected products

  • MongoDB C# Driver Before 3.11.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-26: patched: Fixed in version 3.11.1

References

Related threats