Retour à la veille

CVE-2026-106434

Publié : 8 octobre 2026
Modifié : 8 octobre 2026
Lien officiel NVD
Score CVSS
4.3
MEDIUM

Description détaillée

The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fields, such as a database writer, server, or network intermediary, can cause an affected application to process the supplied bytes as decrypted plaintext.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Références et Patchs