MongoDBGHSA-c4c8-c376-3p6c
Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver
High8.2CVE-2026-88032 · Published Sep 10, 2026
### Impact Cancelling or timing out an encrypted operation while the driver fetches cloud KMS credentials makes it call into freed native memory, crashing or corrupting the application. ### Patches Upgrade reactive driver version to 5.11.1 or later ### Workarounds None. ### References https://jira.mongodb.org/browse/JAVA-6276 https://www.cve.org/CVERecord?id=CVE-2026-88032
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.mongodb:mongodb-crypt Maven | >= 1.4.0, < 5.11.1 | 5.11.1 |
| org.mongodb:mongodb-driver-reactivestreams Maven | >= 4.6.0, < 5.11.1 | 5.11.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | GridFS data disclosure and deletion via query-operator injection in file IDs | Medium6.1 | 1.30.10+1 more |
| Sep 10 | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java Driver | High8.3 | 5.11.1+1 more |
| Sep 10 | Regular expression injection via unescaped characters in LINQ query translation | High7.1 | 3.11.2 |
| Sep 10 | GridFS data disclosure and deletion via query-operator injection in file IDs | Medium6.1 | 3.11.2 |
| Sep 10 | GridFS data deletion via operator-document injection in file IDs | Medium6.1 | 1.17.10+1 more |
| Sep 10 | GridFS data disclosure and deletion via query-operator injection in file IDs | Medium6.1 | 3.9.1 |