Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/MONGOCRYPT-971 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 15:17
Updated : 2026-09-03 17:52
NVD link : CVE-2026-84971
Mitre link : CVE-2026-84971
CVE.ORG link : CVE-2026-84971
JSON object : View
Products Affected
No product.
CWE
CWE-617
Reachable Assertion
