CVE-2026-9735

Source
https://cve.org/CVERecord?id=CVE-2026-9735
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9735.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-9735
Aliases
Downstream
Published
2026-06-09T22:40:55.614Z
Modified
2026-07-25T08:12:10.624235Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Keyfile contents are in MongoDB Server logs
Details

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

Database specific
{
    "cna_assigner": "mongodb",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9735.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.3.0"
                },
                {
                    "fixed": "8.3.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-532"
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "8.3.0"
        },
        {
            "fixed": "8.3.3"
        }
    ],
    "cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

r8.*
r8.3.0

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1759.0,
            "function_hash": "33576969391667528712105414855855095210"
        },
        "id": "CVE-2026-9735-3818d52e",
        "signature_type": "Function",
        "source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
        "target": {
            "function": "_speculateSaslStart",
            "file": "src/mongo/client/authenticate.cpp"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "105051277585384029869713401387324710299",
                "135010353328424632509818700676883262741",
                "230022231509017531526336883388413859957",
                "21785236440502061071534570285577718704",
                "314611412092879437439966455802374359968",
                "4328176094298166889601989525363512001",
                "89833129311893956686513176585485383462",
                "67104821923433815313850425352519867386",
                "66993897057338546953195861906592522514",
                "41622748248584985132494531963597557744",
                "242973420897860388216828233337695113596",
                "336731002354755517834207641772257008949",
                "64002474223761432976487321914411588332",
                "261309617626622354563994167105861925016",
                "229808833034910568928737793619657257065",
                "327973055814987959560058864332639589393",
                "331230983148226970461307129171652554653",
                "194280706403459704585085037893015299868",
                "132169427929260727166827845414640998831",
                "263821533391834434161668531794875587617",
                "231008637408865177850436966867033654335",
                "131209670928832011957508828184726650364",
                "64002474223761432976487321914411588332",
                "261309617626622354563994167105861925016",
                "152599178162463674149335674778053474470",
                "82317842280543420915626715536098646954",
                "89485288152782603664608867313022701634",
                "201049280170827963568948467383659578170",
                "186915239712986481660363218458077044420",
                "81595865256585900407563580384512090789",
                "89485288152782603664608867313022701634",
                "201049280170827963568948467383659578170"
            ]
        },
        "id": "CVE-2026-9735-80a3d3f5",
        "signature_type": "Line",
        "source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
        "target": {
            "file": "src/mongo/client/authenticate.cpp"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 2313.0,
            "function_hash": "20399944836295365806244165546970965254"
        },
        "id": "CVE-2026-9735-99e1e8a5",
        "signature_type": "Function",
        "source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
        "target": {
            "function": "saslClientAuthenticateImpl",
            "file": "src/mongo/client/sasl_client_authenticate_impl.cpp"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "119297248915920219031821473937269301824",
                "192950127050229143070957758609674490481",
                "299256134244687864194021167969650322418",
                "78705388978130039955877200458257143577",
                "321869386180767067962050016171660673429",
                "92304406178298145235033043329826640960",
                "203486625542267065639036914103785025824",
                "101091632339192440179784421579332741865",
                "121174813050634776452676460079189488323",
                "128019987876497809896042531600850302807",
                "254894470578114612803585286215406515998",
                "214382625466148222914899976163699517733",
                "190404496706438243159513143102836777584",
                "56154081985503966229462899327055184543",
                "208419707775319461290978685733013608031",
                "112980909939898786886727276248725730797",
                "125593633845177966189813606560474867521",
                "171922900114146216740577553907126530807",
                "101091632339192440179784421579332741865",
                "264963333426305115134532843740947636372",
                "89987837705424899310632089922787348176",
                "57891838713164422666568581445619931080",
                "60290105400638828282268502673375231284",
                "142183950137575110969330755820960546057",
                "56154081985503966229462899327055184543",
                "208419707775319461290978685733013608031"
            ]
        },
        "id": "CVE-2026-9735-bae78291",
        "signature_type": "Line",
        "source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
        "target": {
            "file": "src/mongo/client/sasl_client_authenticate_impl.cpp"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1778.0,
            "function_hash": "45101164990253539481215998889390091905"
        },
        "id": "CVE-2026-9735-e4b18909",
        "signature_type": "Function",
        "source": "https://github.com/mongodb/mongo/commit/065930ba70a49b0347dc5b8f0c04851770a68af2",
        "target": {
            "function": "authX509",
            "file": "src/mongo/client/authenticate.cpp"
        }
    }
]
vanir_signatures_modified
"2026-07-25T08:12:10Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9735.json"