Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN938 _____________________________________________________________________ DATE : 25/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running mongo-c-driver (C) versions prior to 1.30.12, 2.5.5, mongodb (PECL), mongodb/mongodb-extension (Composer) versions prior to 1.21.10, 2.1.10, 2.5.3, pymongo (pip) versions prior to 4.18.2, MongoDB COMPASS versions prior to 1.49.12. ===================================================================== https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46 https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv https://github.com/mongodb-js/compass/releases/tag/v1.49.12 _____________________________________________________________________ Heap buffer overflow via mid-scan command list growth in client topology monitoring High kevinAlbs published GHSA-frjf-h5jg-4v46 Package mongo-c-driver (C) Affected versions >= 1.0.0, < 1.30.12 >= 2.0.0 < 2.5.5 Patched versions 1.30.12 2.5.5 Description Impact An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly. Patches Fixed in 1.30.12 and 2.5.5. Workarounds None. References https://jira.mongodb.org/browse/CDRIVER-6404 Severity High 8.3/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity Low Attack Requirements Present Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality None Integrity Low Availability High Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N CVE ID CVE-2026-96746 Weaknesses No CWEs _____________________________________________________________________ PHP object injection via unsuppressible __pclass class inference in command monitoring events Moderate kevinAlbs published GHSA-cmvj-vxvq-rh2c Package mongodb (PECL) Affected versions < 1.21.10 >= 2.0.0, < 2.1.10 >= 2.2.0, < 2.5.3 Patched versions 1.21.10 2.1.10 2.5.3 mongodb/mongodb-extension (Composer) Affected versions < 1.21.10 >= 2.0.0, < 2.1.10 >= 2.2.0, < 2.5.3 Patched versions 1.21.10 2.1.10 2.5.3 Description Impact Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application. Patches Fixed in 1.21.10, 2.1.10, 2.5.3 Workarounds Can check BSON does not contain __pclass fields. References https://jira.mongodb.org/browse/PHPC-2743 Severity Moderate 6.3/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity High Attack Requirements None Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality Low Integrity Low Availability Low Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE ID CVE-2026-96745 Weaknesses No CWEs _____________________________________________________________________ PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding High Jibola published GHSA-v4x9-3549-crwv Package pymongo (pip) Affected versions 1.9 Patched versions 4.18.2 Description An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process. Severity High 7.5/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Local Attack Complexity Low Attack Requirements Present Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality High Integrity High Availability High Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE ID CVE-2026-96749 Weaknesses Weakness CWE-190 _____________________________________________________________________ Release v1.49.12 What's Changed New Features feat(compass-editor): add hover styling to autocomplete dropdown item COMPASS-8227 Bug Fixes fix(import-export): better escape for csv values COMPASS-10815 fix(schema): escape tooltip label to make sure samples are shown correctly COMPASS-10814 fix(sidebar, collections-databases-list): escape database names similar to collection names COMPASS-10810 Warning This release contains a fix for CVE-2026-96750 that affects all versions of Compass starting from 1.44.0 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================