C Driver
32 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for C Driver, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
C Driver CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 6 |
| 2026-09 | 15 |
Severity
How the 32 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High8
- Medium21
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting C Driver.
- CVE-2026-96746Heap buffer overflow via mid-scan command list growth in client topology monitoring6.5
- CVE-2026-93395Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()5.3
- CVE-2026-93394libmongoc SCRAM client nonce-validation bypass3.7
- CVE-2026-93393Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream8.1
- CVE-2026-88036GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver8.3
- CVE-2026-88035Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver4.7
- CVE-2026-88034GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver8.3
- CVE-2026-88026Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver6.5
- CVE-2026-88025GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver8.3
- CVE-2026-84963Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser5.3
- CVE-2026-84964Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client5.9
- CVE-2026-84965Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds5.1
- CVE-2026-84966BSON element injection via NUL-embedded document keys in builder append5.1
- CVE-2026-84969Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output3.7
- CVE-2026-84970Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser6.2
Product grouping is registry-driven, with AI assist and human review. How it works