CVE-2026-19004

Source
https://cve.org/CVERecord?id=CVE-2026-19004
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19004.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19004
Published
2026-08-12T20:33:13.882Z
Modified
2026-08-15T11:31:22.214920045Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N CVSS Calculator
Summary
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters
Details

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.

Database specific
{
    "cna_assigner": "mongodb",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19004.json",
    "cwe_ids": [
        "CWE-122"
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo-bi-connector-odbc-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-bi-connector-odbc-driver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "1.4.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.6-beta
v1.4.7
v1.4.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19004.json"