CVE-2026-106431
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Overflow in MongoDB C Driver

Vulnerability report for CVE-2026-106431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
MongoDB C Driver 0.5.0
MongoDB C Driver 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an off-by-one error in the BSON bulk document writer of the MongoDB C Driver. It occurs when a document ends at a specific buffer boundary, causing the system to write one extra zero byte past the allocated heap memory. This can corrupt adjacent process memory or crash the application.

Detection Guidance

This vulnerability requires specific conditions to trigger, such as using the BSON bulk-writer API with precise document sizes. Detection may involve code review to check for use of the affected API and buffer boundary conditions. No direct commands are provided in the context to detect this issue.

Impact Analysis

An attacker who can control the size of documents processed by the application could exploit this flaw to corrupt memory or terminate the process. This may lead to denial-of-service conditions or potential code execution in the worst case.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if it leads to unauthorized memory access or data corruption in systems handling sensitive personal or health data. However, the provided CVE details do not explicitly link this issue to compliance requirements.

Mitigation Strategies

Immediate mitigation steps include updating the MongoDB C Driver to a patched version if available. Avoid using the BSON bulk-writer API if possible. Monitor application logs for crashes or memory corruption near document boundaries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart