Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-106433: MongoDB libmongocrypt may crash or corrupt data with duplicate masterKey fields
CVE-2026-106433 · published 1 day ago
Summary
The MongoDB libmongocrypt library can mishandle key records that contain two masterKey entries. If someone who can change those key records, or a server that sends them, does so, it can cause the application using the library to stop working or to have its memory corrupted. Update to the latest library version or ensure key records never contain duplicate masterKey fields to avoid this issue.
What to do
- Update mongodb libmongocrypt to version 1.20.5 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | mongodb | libmongocrypt | < 1.20.5 |
| Debian:12 | debian | libmongocrypt | All versions |
Original advisory text
Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault documents, or a server that returns such a key document, can cause invalid memory access and invalid frees in the client process. This can terminate the application or corrupt process memory.
References
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-843Type Confusion
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta