CVE-2026-88032

Source
https://cve.org/CVERecord?id=CVE-2026-88032
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88032.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88032
Downstream
Published
2026-09-10T18:02:13Z
Modified
2026-09-18T03:48:37Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver
Details

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88032.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.2.0"
                },
                {
                    "fixed": "5.11.1"
                },
                {
                    "introduced": "1.4.0"
                },
                {
                    "fixed": "5.11.1"
                },
                {
                    "introduced": "4.6.0"
                },
                {
                    "fixed": "5.11.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo-java-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-java-driver
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:*",
    "extracted_events": [
        {
            "introduced": "4.2.0"
        },
        {
            "fixed": "5.11.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

r4.*
r4.10.0
r4.10.0-alpha0
r4.10.0-alpha1
r4.11.0
r4.2.0
r4.3.0
r4.3.0-beta1
r4.3.0-beta2
r4.3.0-beta3
r4.3.0-beta4
r4.4.0
r4.4.0-beta1
r4.4.0-beta2
r4.5.0
r4.5.0-beta0
r4.6.0
r4.6.0-alpha0
r4.7.0
r4.7.0-beta0
r4.8.0-beta0
r4.8.0-rc0
r4.9.0
r5.*
r5.0.0
r5.0.0-beta0
r5.1.0
r5.11.0
r5.3.0-beta0
r5.4.0-alpha0
r5.6.0-alpha0
r5.7.0-alpha0
r5.7.0-beta0
r5.7.0-beta1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88032.json"