VYPR

Java Driver

by MongoDB

CVEs (3)

  • CVE-2026-88033HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2021-20328MedFeb 25, 2021
    risk 0.42cvss 6.4epss 0.00

    Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in…

  • CVE-2026-88032MedSep 10, 2026
    risk 0.38cvss 5.9epss 0.00

    A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled…