Junglewise Threat Intelligence

CVE-2026-9100: MongoDB C Driver memory leak and DoS in legacy GridFS API

CVE-2026-9100 · Severity: medium · CVSS 5.9 · Published 2026-05-20

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C Driver, a software component used by applications to communicate with MongoDB databases, contains a vulnerability in its legacy GridFS file storage API. If an attacker can place specially crafted file metadata into the database, applications reading those files may crash or inadvertently leak sensitive information from their memory. This could lead to service disruptions or the exposure of internal application data.

Technical details

A vulnerability exists in the legacy GridFS API of the MongoDB C Driver (libmongoc) due to improper validation of file metadata retrieved from the database. Specifically, the driver does not adequately check arithmetic operations or index positions when processing GridFS documents. An attacker with the ability to insert or modify documents in a GridFS collection can trigger a division-by-zero error, causing a Denial of Service (DoS), or an out-of-bounds read, leading to information disclosure of process memory. The attack requires network access and low-level privileges to modify database contents. The issue is addressed in versions 1.30.8 and 2.2.4.

Affected products

  • MongoDB C Driver (libmongoc) Versions prior to 1.30.8 and 2.2.4

Timeline

  • 2026-04-02: other: Issue reported internally/created in Jira
  • 2026-04-07: patched: Issue resolved/fixed in development
  • 2026-05-20: advisory: CVE published and NVD entry created

References

Related threats