A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
{ "binaries": [ { "binary_name": "libbson-1.0-0", "binary_version": "1.16.1-1ubuntu0.1~esm1" }, { "binary_name": "libmongoc-1.0-0", "binary_version": "1.16.1-1ubuntu0.1~esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4359.json"
{ "binaries": [ { "binary_name": "libbson-1.0-0", "binary_version": "1.21.0-1ubuntu0.1~esm1" }, { "binary_name": "libmongoc-1.0-0", "binary_version": "1.21.0-1ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libbson-1.0-0t64", "binary_version": "1.26.0-1.1ubuntu2+esm1" }, { "binary_name": "libmongoc-1.0-0t64", "binary_version": "1.26.0-1.1ubuntu2+esm1" } ] }
{ "binaries": [ { "binary_name": "libbson-1.0-0t64", "binary_version": "1.30.4-1ubuntu1" }, { "binary_name": "libmongoc-1.0-0t64", "binary_version": "1.30.4-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "libbson2-2", "binary_version": "2.2.2-1" }, { "binary_name": "libmongoc2-2", "binary_version": "2.2.2-1" } ] }