Executive brief
MongoDB's libmongocrypt is a client-side encryption library that handles encrypted data decryption in database applications. An attacker who can inject a malformed encrypted value into the decryption path can trigger an internal validation failure that crashes the application, causing a denial of service. This could disrupt business operations for applications relying on MongoDB's encrypted field functionality.
Technical details
The vulnerability is a client-side denial of service flaw in the decryption path of libmongocrypt caused by improper handling of unexpectedly small (undersized) encrypted payload values. When the library attempts to decrypt a malformed payload with insufficient data, it fails an internal validation check and aborts the process. An attacker with the ability to place a crafted encrypted value where an application will decrypt it, or control network responses, can trigger this abort condition. The issue was fixed in version 1.20.4 of libmongocrypt.
Affected products
- MongoDB libmongocrypt before 1.20.4
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fixed in version 1.20.4