CVE-2026-106430 — The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API.
Description
The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An authenticated actor who can influence a name passed by an affected application can cause the application to read distinct values from an unintended field or rename an unintended collection. These operations use the application's existing database credentials.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCoraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 6h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 6h ago
Coraza has Cookie Parser Confusion
OSV · 6h ago
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
OSV · 6h ago
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
OSV · 6h ago
CVE-2026-106505 — Backstage is an open framework for building developer portals.
CVE-2026-106505 · 2d ago