C Driver
Vendor:
First CVE: Apr 24, 2020 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact C Driver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2020
6 years ago
Most Recent CVE
May 6, 2026
80 days ago
CVE Severity & Scoring
C Driver8 CVEs
25%
13%
63%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (50.0%)
Network4 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6691HIGH The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network | May 6, 2026 | 7.8 | 32 | NO | NO |
CVE-2024-7553HIGH Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the ap | Aug 7, 2024 | 7.8 | 25 | NO | NO |
CVE-2026-6231HIGH The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed o | Apr 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2021-32050HIGH Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain secu | Aug 29, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-0437HIGH When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versio | Jan 12, 2024 | 7.5 | 19 | NO | NO |
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. | Mar 17, 2026 | 3.7 | 18 | NO | NO |
A mongoc_bulk_operation_t may read invalid memory if large options are passed. | Nov 18, 2025 | 3.3 | 16 | NO | NO |
CVE-2020-12135MEDIUM bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have a | Apr 24, 2020 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For C Driver
Top CWEs
Versions
No cataloged versions.