Bug 2548209 (CVE-2026-106429) - CVE-2026-106429 libmongocrypt: libmongocrypt: Denial of Service via integer underflow in KMS endpoint parsing
Summary: CVE-2026-106429 libmongocrypt: libmongocrypt: Denial of Service via integer u...
Keywords:
Status: NEW
Alias: CVE-2026-106429
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2548571 2548575
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 19:12 UTC by OSIDB Bzimport
Modified: 2026-10-09 12:54 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 19:12:34 UTC
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.


Note You need to log in before you can comment on or make changes to this bug.