CVE-2026-106438
Last modified
CVE-2026-106438 is a medium-severity vulnerability rated 4/10 on the CVSS scale. An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text.
Description
An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MongoDB | C Driver | >= 1.4.0, < 1.30.13; >= 2.0.0, < 2.5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106438?
How severe is CVE-2026-106438?
How do I fix CVE-2026-106438?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-106431An off-by-one error in the BSON bulk document writer in the …5.7
- CVE-2026-106432The BSON encoder in the MongoDB PHP Driver converts a string…3.6
- CVE-2026-106433Improper state management in MongoDB libmongocrypt can cause…8.8
- CVE-2026-106434The explicit decryption component of MongoDB libmongocrypt c…4.3
- CVE-2026-106436The BSON encoder in the MongoDB PHP Driver does not check so…4.8
- CVE-2026-106437The BSON buffer-reservation API in the MongoDB C Driver can …6.2
- CVE-2026-106439Hydra is a framework for elegantly configuring complex appli…8.5
- CVE-2026-10644The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mch…3.1
- CVE-2026-106440Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106441Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106442Hydra is a framework for elegantly configuring complex appli…7.8
- CVE-2026-106443WeasyPrint helps web developers to create PDF documents. Pri…8.8
Are you affected by CVE-2026-106438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
