CVE-2026-19001

Source
https://cve.org/CVERecord?id=CVE-2026-19001
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19001.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19001
Published
2026-08-12T20:27:02.913Z
Modified
2026-08-15T11:31:26.303622744Z
Severity
  • 9.5 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N CVSS Calculator
Summary
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names
Details

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19001.json"
}
References

Affected packages

Git / github.com/mongodb/mongo-bi-connector-odbc-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-bi-connector-odbc-driver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "1.4.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.6-beta
v1.4.7
v1.4.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19001.json"