Retour à la veille

CVE-2026-106438

Publié : 8 octobre 2026
Modifié : 8 octobre 2026
Lien officiel NVD
Score CVSS
4
MEDIUM

Description détaillée

An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Références et Patchs