DEBIAN-CVE-2026-84963
Dashboard / Vulnerabilities / DEBIAN-CVE-2026-84963
Summary:
Details: An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.
Affected packages
Package
Name: mongo-c-driver
Purl: pkg:deb/debian/mongo-c-driver?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
1.23.1-1
1.23.1-1+deb12u1
1.23.1-1+deb12u2
1.23.1-1+deb12u3
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
