Source: mongo-java-driver Version: 3.6.3-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for mongo-java-driver. CVE-2026-88032[0]: | A use-after-free in the reactive client-side encryption component of | the MongoDB Java Driver can cause native resources to be freed while | an affected encrypted operation is still using them when the | operation is cancelled. A party able to cause such an operation to | be cancelled may cause the hosting application process to terminate. | Reaching the issue requires an affected reactive encryption | configuration that retrieves KMS credentials on demand. CVE-2026-88033[1]: | Improper neutralization of special elements in data query logic in | the GridFS component of the MongoDB Java Driver can cause a caller- | supplied structured file identifier to be interpreted as a query | condition rather than as a literal identifier. An authenticated user | who can influence the identifier passed by an affected application | may obtain stored file content beyond the intended target or cause | all GridFS file chunks in the affected bucket to be removed, | rendering stored file content unreadable. The affected rename | operation may also rename a stored file other than the intended | target. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-88032 https://www.cve.org/CVERecord?id=CVE-2026-88032 [1] https://security-tracker.debian.org/tracker/CVE-2026-88033 https://www.cve.org/CVERecord?id=CVE-2026-88033 Regards, Salvatore

