CVE-2026-84964CWE-415

CVE-2026-84964

Medium · published September 3, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
4.2
In the wild
Unconfirmed
What it is

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An unauthenticated party acting as the trusted endpoint may cause the connecting client application to terminate unexpectedly.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.2 · CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00147 · 4.2th percentile
Weakness
CWE-415 · Double Free
Published
2026-09-03T20:18Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 15:02Z
    Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
    cvelistv5