CVE-2026-106438: Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver
An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value different from the supplied text. An actor who can provide a decimal string to an embedding application, including through Extended JSON parsing, can cause the application to store or use an incorrect numeric value.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications embedding the MongoDB C Driver are exposed if they accept decimal strings from an actor and parse them as Decimal128. This includes applications that accept Extended JSON containing Decimal128 values.
What does an attacker need to exploit it?
An attacker needs the ability to supply a Decimal128 decimal string to the embedding application. The affected inputs are certain over-precision values that contain leading zeros.
What is the impact of successful exploitation?
The supplied decimal text can be accepted when it should be rejected, and the resulting Decimal128 value differs from the supplied text. The application may then store or use an incorrect numeric value.