Junglewise Threat Intelligence

CVE-2026-93393: MongoDB C Driver heap overflow in TLS transport layer

CVE-2026-93393 · Severity: high · CVSS 8.1 · Published 2026-09-17

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C Driver, a library used by applications to communicate with MongoDB databases, contains a heap-based buffer overflow vulnerability in its Windows TLS (encryption) layer. A malicious MongoDB server or network attacker can exploit this by sending specially crafted encrypted data, causing the client application to crash, leak sensitive memory, or potentially execute arbitrary code—all without requiring any user credentials or interaction.

Technical details

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows Secure Channel backend. The vulnerability occurs during TLS record processing after the handshake completes, triggered by a failure to properly validate decrypted TLS record size. A remote endpoint can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required since the processing occurs before application-level authentication. The vulnerability has been patched in versions 1.30.11 and 2.5.4.

Affected products

  • MongoDB C Driver before 1.30.11 and 2.5.4

Timeline

  • 2026-09-17: disclosed
  • 2026-09-18: patched: Fixed in C Driver 1.30.11 and 2.5.4

References

Related threats