Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-106433: MongoDB libmongocrypt may crash or corrupt data with duplicate masterKey fields

CVE-2026-106433 · published 1 day ago
Summary

The MongoDB libmongocrypt library can mishandle key records that contain two masterKey entries. If someone who can change those key records, or a server that sends them, does so, it can cause the application using the library to stop working or to have its memory corrupted. Update to the latest library version or ensure key records never contain duplicate masterKey fields to avoid this issue.

What to do
  • Update mongodb libmongocrypt to version 1.20.5 or later.
Affected software
Ecosystem VendorProductAffected versions
– mongodb libmongocrypt < 1.20.5
Debian:12 debian libmongocrypt All versions
Original advisory text
Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-843Type Confusion
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-106433 · MITRE
Track software like this
Free during beta