Vulnerability Description
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-93393?
CVE-2026-93393 is a vulnerability with a CVSS score of 8.1 (HIGH). A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the dri...
How severe is CVE-2026-93393?
CVE-2026-93393 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-93393?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.