CVE Tools

C Driver

32 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for C Driver, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

C Driver CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
C Driver CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-031
2026-041
2026-052
2026-060
2026-070
2026-086
2026-0915

Severity

How the 32 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High825%
  • Medium2166%
  • Low39%

Latest CVEs

The 15 most recently published vulnerabilities affecting C Driver.

  1. CVE-2026-96746Heap buffer overflow via mid-scan command list growth in client topology monitoring6.5
  2. CVE-2026-93395Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()5.3
  3. CVE-2026-93394libmongoc SCRAM client nonce-validation bypass3.7
  4. CVE-2026-93393Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream8.1
  5. CVE-2026-88036GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver8.3
  6. CVE-2026-88035Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver4.7
  7. CVE-2026-88034GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver8.3
  8. CVE-2026-88026Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver6.5
  9. CVE-2026-88025GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver8.3
  10. CVE-2026-84963Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser5.3
  11. CVE-2026-84964Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client5.9
  12. CVE-2026-84965Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds5.1
  13. CVE-2026-84966BSON element injection via NUL-embedded document keys in builder append5.1
  14. CVE-2026-84969Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output3.7
  15. CVE-2026-84970Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser6.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store