CVE-2026-93393: Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream

Published Sep 17, 2026
·
Updated

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to, or an attacker able to impersonate or redirect the client's connection, can cause the driver to write attacker-supplied data outside the bounds of a heap allocation while processing incoming encrypted traffic. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Successful exploitation may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.

Affected Software

1 affected component
MongoDB MongoDB C driver

Event History

Sep 17, 2026
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using the MongoDB C Driver built with the Windows platform TLS backend are exposed when they connect to a remote endpoint that can send the malicious encrypted TLS traffic. The issue affects the client process rather than requiring compromise of the MongoDB server.

2

What access does an attacker need to exploit this?

An attacker needs to control the remote endpoint the client connects to, or be able to impersonate or redirect that connection. No authentication credentials or user interaction are required because the vulnerable processing happens before application-level authentication.

3

What can be done if patching is not immediately possible?

Limit connections to trusted, expected remote endpoints and prevent attackers from redirecting or impersonating those connections. This reduces exposure to malicious TLS peers, although the provided information does not identify a complete workaround.

4

How might exploitation affect an application?

Successful exploitation may corrupt memory in the client process, disclose adjacent heap memory, or terminate the process. The vulnerability is a heap-based buffer overflow while processing incoming encrypted TLS traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203