CVE-2026-106429: Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.
Affected Software
Event History
Frequently Asked Questions
Who can trigger this denial of service?
An authenticated user who can modify a key document in the key vault collection can trigger it. It can also be triggered if the application accepts a malicious KMS endpoint during key creation.
What KMS endpoint format is relevant to exploitation?
The affected parsing condition involves a KMS endpoint with a colon appearing after its path or query component.
What is the impact if exploitation succeeds?
The integer underflow can cause an allocation failure that terminates the application process, resulting in denial of service. The issue does not access memory outside allocated bounds.
How can teams determine whether they may be exposed?
Review whether authenticated users can modify key vault key documents and whether application input can supply KMS endpoints during key creation. Exposure exists where either path permits the malformed endpoint condition.