Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-6419 |
|
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value. | |
| Title | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver | |
| Weaknesses | CWE-682 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-10-08T19:21:43.595Z
Reserved: 2026-10-06T16:40:40.579Z
Link: CVE-2026-106438
Updated: 2026-10-08T19:20:44.186Z
Status : Awaiting Analysis
Published: 2026-10-08T19:16:59.703
Modified: 2026-10-08T20:49:23.240
Link: CVE-2026-106438
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:30:18Z