Repository navigation
Security: mongodb/libmongocrypt
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Application denial of service via malformed KMS endpoint in MongoDB libmongocryptGHSA-4xwm-g7wm-6635 published
Oct 8, 2026 by kevinAlbsHigh -
Authenticated KMS request forgery via CRLF injection in GCP key identifier stringsGHSA-j29g-r9cq-fh35 published
Sep 3, 2026 by kevinAlbsModerate -
Unrecognized payload acceptance in explicit decryption in MongoDB libmongocryptGHSA-9f57-899g-2985 published
Oct 8, 2026 by kevinAlbsModerate -
Heap corruption via duplicate masterKey fields in MongoDB libmongocryptGHSA-5x4p-pwv3-hgfh published
Oct 8, 2026 by kevinAlbsHigh -
Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocryptGHSA-8g9w-8cw9-q38w published
Aug 27, 2026 by kevinAlbsModerate -
Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption pathGHSA-8g5h-p67q-9m5j published
Sep 3, 2026 by kevinAlbsHigh
Learn more about advisories related to mongodb/libmongocrypt in the GitHub Advisory Database