CVE-2026-4359Disclosure(mongodb / c_driver)

LOWCVSS 3.7 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mongodb c_driver systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-158

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • c_driver

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-17); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
c_driver

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-17: 3Mentions · 2026-03-18: 2Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 203-1703-18
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-173
Disclosure2General1
2026-03-182
Disclosure1Patch1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4359 A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. https://www.cve.org/CVERecord?id=CVE-2026-4359

    Post summary

    CVE-2026-4359 is a crash vulnerability where a malformed HTTP response from a compromised cloud server or MITM attacker can terminate applications using the MongoDB C driver; no exploit, patch, or active exploitation information is provided.

    00000171
    56.7K followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Patch

    Security alert: CVE-2026-4359 — MongoDB C driver remote DoS via malformed HTTP response. If you use the C driver, see affected versions and mitigation steps: https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4359

    Post summary

    The alert reports CVE-2026-4359 as a remote DoS in the MongoDB C driver, provides mitigation guidance and a link to affected versions, but does not include PoC, exploit code, or evidence of active exploitation.

    000000
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4359 MongoDB C Driver Remote Denial of Service via Malformed HTTP Response https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4359

    Post summary

    CVE-2026-4359 is a remote denial‑of‑service vulnerability in the MongoDB C driver triggered by malformed HTTP responses, with no evidence of PoC, exploitation, or mitigation mentioned.

    0000053
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4359 - Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer Intel Report: https://ift.tt/xKNYFcZ

    Post summary

    The post briefly alerts to CVE-2026-4359, describing its buffer over-read flaw but provides no PoC, tool, or patch information, suggesting a general notice.

    0000044
    335 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4359 - Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer Intel Report: https://ift.tt/wEroRp7

    Post summary

    An Intel report discloses CVE-2026-4359 as a heap‑buffer‑over‑read flaw in MongoDB's HTTP sending routine, with no PoC, exploit, active exploitation, or patch mentioned.

    0000044
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbc_driver-mongodb-

Explore more