Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:LMongodb Rust Driver
APPMongodb2.0.0 – 2.8.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-11695HIGH8.0same product
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability...
CVE-2021-20332MEDIUM4.2same product
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate conn...
CVE-2026-13072CRITICAL9.2PL ✓same vendor
Heap Buffer Overflow w MongoDB (tryb compute) podczas przetwarzania BSON
CVE-2020-7610CRITICAL9.8PL ✓same vendor
Deserializacja niezaufanych danych w bibliotece MongoDB BSON (przed 1.1.4)
CVE-2017-15535CRITICAL9.1PL ✓same vendor
MongoDB: podatność w kompresji protokołu sieciowego — DoS i modyfikacja pamięci