{"id":"CVE-2026-93393","summary":"Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream","details":"A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.","modified":"2026-10-08T02:52:36.495063566Z","published":"2026-09-17T20:26:38.911Z","database_specific":{"cna_assigner":"mongodb","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93393.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.3.0"},{"last_affected":"2.3.3"},{"introduced":"2.2.0"},{"last_affected":"2.2.4"},{"introduced":"2.1.0"},{"last_affected":"2.1.2"},{"introduced":"2.0.0"},{"last_affected":"2.0.2"},{"introduced":"1.30.0"},{"last_affected":"1.30.8"},{"introduced":"1.29.0"},{"last_affected":"1.29.2"},{"introduced":"1.28.0"},{"last_affected":"1.28.1"},{"introduced":"1.27.0"},{"last_affected":"1.27.6"},{"introduced":"1.26.0"},{"last_affected":"1.26.2"},{"introduced":"1.25.0"},{"last_affected":"1.25.4"},{"introduced":"1.24.0"},{"last_affected":"1.24.4"},{"introduced":"2.4.0"},{"last_affected":"2.4.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/CDRIVER-6417"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93393.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93393"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo-c-driver","events":[{"introduced":"1cb8a16e863cea77a61530b832ed2c7c1dc5c065"},{"fixed":"c3febede70c3b8955905f4de519326069e80483c"},{"introduced":"9ad750264dbdf6eb23efa6859b7488a8275ae693"},{"fixed":"ad87ab88907a0105823469fb5d393ed717bed9ba"}],"database_specific":{"extracted_events":[{"introduced":"1.10.0"},{"fixed":"1.30.11"},{"introduced":"2.2.0"},{"fixed":"2.5.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93393.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}