DEBIAN-CVE-2026-88032

Source
https://security-tracker.debian.org/tracker/CVE-2026-88032
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88032.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-88032
Upstream
Published
2026-09-10T19:17:40Z
Modified
2026-09-17T09:00:17Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.

References

Affected packages

Debian:12 / mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/debian/mongo-java-driver?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2
3.6.3-2.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88032.json"

Debian:13 / mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/debian/mongo-java-driver?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2
3.6.3-2.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88032.json"

Debian:14 / mongo-java-driver

Package

Name
mongo-java-driver
Purl
pkg:deb/debian/mongo-java-driver?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.3-2
3.6.3-2.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88032.json"