Source: mongo-java-driver
Version: 3.6.3-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for mongo-java-driver.

CVE-2026-88032[0]:
| A use-after-free in the reactive client-side encryption component of
| the MongoDB Java Driver can cause native resources to be freed while
| an affected encrypted operation is still using them when the
| operation is cancelled. A party able to cause such an operation to
| be cancelled may cause the hosting application process to terminate.
| Reaching the issue requires an affected reactive encryption
| configuration that retrieves KMS credentials on demand.


CVE-2026-88033[1]:
| Improper neutralization of special elements in data query logic in
| the GridFS component of the MongoDB Java Driver can cause a caller-
| supplied structured file identifier to be interpreted as a query
| condition rather than as a literal identifier. An authenticated user
| who can influence the identifier passed by an affected application
| may obtain stored file content beyond the intended target or cause
| all GridFS file chunks in the affected bucket to be removed,
| rendering stored file content unreadable. The affected rename
| operation may also rename a stored file other than the intended
| target.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88032
    https://www.cve.org/CVERecord?id=CVE-2026-88032
[1] https://security-tracker.debian.org/tracker/CVE-2026-88033
    https://www.cve.org/CVERecord?id=CVE-2026-88033

Regards,
Salvatore

Reply via email to