Junglewise Threat Intelligence

CVE-2026-84964: MongoDB C Driver double free in TLS certificate revocation checking

CVE-2026-84964 · Severity: medium · CVSS 5.9 · Published 2026-09-03

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C Driver contains a memory safety bug in its OpenSSL-based TLS certificate revocation checking during the handshake process. A malicious or compromised TLS server that the client already trusts can send specially crafted certificate data, causing the client application to crash unexpectedly. This impacts availability and operational reliability for applications using the driver.

Technical details

This vulnerability is a double-free in the OpenSSL-based TLS certificate revocation checking path (OCSP check) of the MongoDB C Driver. The vulnerability is triggered during the TLS handshake when the server sends specially formed certificate data, causing the same heap object to be released twice. The attack vector is network-based and requires the attacker to act as a trusted TLS endpoint that the client is already connecting to. An unauthenticated attacker in this position can cause a denial of service by crashing the connecting client application. The vulnerability was fixed in versions 2.5.2 and 1.30.9.

Affected products

  • MongoDB C Driver before 1.30.9, 2.5.2

Timeline

  • 2026-09-03: disclosed: CVE-2026-84964 published
  • 2026-09-04: patched: Fix released in C Driver 2.5.2 and 1.30.9

References

Related threats