CVE-2026-106438
Awaiting Analysis Awaiting Analysis - Queue

Decimal128 Parsing Flaw in MongoDB C Driver

Vulnerability report for CVE-2026-106438, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
MongoDB C Driver 1.4.0
MongoDB C Driver 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-682 The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an incorrect calculation in Decimal128 string parsing in the MongoDB C Driver. It accepts over-precision inputs with leading zeros instead of rejecting them, leading to a stored or used numeric value different from the input text. This can occur through Extended JSON parsing or when providing decimal strings to embedding applications.

Detection Guidance

This vulnerability involves incorrect parsing of Decimal128 strings in the MongoDB C Driver. Detection requires checking if your application uses the MongoDB C Driver and if it processes decimal strings with leading zeros. Review application logs for parsing errors or unexpected numeric values. No specific commands are provided in the context.

Impact Analysis

An attacker who can provide a decimal string to an application using the MongoDB C Driver could cause incorrect numeric values to be stored or processed. This may lead to financial errors, data corruption, or incorrect calculations in applications relying on precise decimal values.

Compliance Impact

This vulnerability could impact compliance by causing incorrect data storage or processing, potentially violating integrity requirements in GDPR or HIPAA. If applications handle regulated data with this flaw, it may lead to non-compliance due to data inaccuracies or integrity breaches.

Mitigation Strategies

Immediately update the MongoDB C Driver to the latest patched version. If updating is not possible, restrict input validation to reject decimal strings with leading zeros. Review stored data for incorrect numeric values caused by this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106438. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart