VYPR

mongocryptd

by MongoDB

CVEs (4)

  • CVE-2026-84971MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it,…

  • CVE-2026-8201MedMay 13, 2026
    risk 0.42cvss 6.4epss 0.00

    A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue…

  • CVE-2026-84962MedSep 3, 2026
    risk 0.27cvss 4.2epss 0.00

    An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.

  • CVE-2024-8013LowOct 28, 2024
    risk 0.14cvss 2.2epss 0.00

    A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue…