A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/JAVA-6276 |
|
History
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting application process to terminate. Reaching the issue requires an affected reactive encryption configuration that retrieves KMS credentials on demand. | |
| Title | Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2026-09-10T18:02:13.806Z
Updated: 2026-09-10T23:36:07.265Z
Reserved: 2026-09-09T19:49:39.184Z
Link: CVE-2026-88032
Updated: 2026-09-10T18:28:38.587Z
Status : Awaiting Analysis
Published: 2026-09-10T19:17:40.533
Modified: 2026-09-11T00:19:58.350
Link: CVE-2026-88032
No data.