Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/mongodb/libmongocrypt

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-106434 is a medium severity vulnerability in MongoDB libmongocrypt affecting versions from 1.5.0 up to but not including 1.20.5. The issue involves improper validation of the integrity check value during explicit decryption, where unrecognized encrypted payloads may be returned unchanged instead of triggering a decryption error. This flaw could allow an actor capable of modifying stored encrypted fields to cause the application to treat manipulated ciphertext as decrypted plaintext.

Join the discussion

CVE-2026-106433 is a high-severity vulnerability in MongoDB's libmongocrypt library involving improper state management that leads to type confusion. This flaw occurs when cleaning up a key document containing duplicate masterKey fields, causing provider-specific data to be treated as an incompatible type. An authenticated actor able to modify key vault documents or a server returning such a key document can trigger invalid memory access and invalid frees in the client process, potentially terminating the application or corrupting memory.

Join the discussion

CVE-2026-106429 is an integer underflow vulnerability in the KMS endpoint-parsing logic of MongoDB libmongocrypt. It can cause an allocation failure that terminates the application process. This occurs when an authenticated user modifies a key document in the key vault collection or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The vulnerability does not result in memory access outside allocated bounds.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/mongodb/libmongocrypt
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses