CVE-2026-88032

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.
References
Link Resource
https://jira.mongodb.org/browse/JAVA-6276 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:*

History

16 Sep 2026, 15:51

Type Values Removed Values Added
CPE cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:*
References () https://jira.mongodb.org/browse/JAVA-6276 - () https://jira.mongodb.org/browse/JAVA-6276 - Vendor Advisory
First Time Mongodb
Mongodb java Driver

Information

Published : 2026-09-10 19:17

Updated : 2026-09-16 15:51


NVD link : CVE-2026-88032

Mitre link : CVE-2026-88032

CVE.ORG link : CVE-2026-88032


JSON object : View

Products Affected

mongodb

  • java_driver
CWE
CWE-416

Use After Free