CVE-2026-106435
Awaiting Analysis Awaiting Analysis - Queue

Buffer Overflow in MongoDB Python Driver Binary Accelerator

Vulnerability report for CVE-2026-106435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MongoDB Python Driver 0.10.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MongoDB Python Driver's binary accelerator has a buffer overflow vulnerability when processing malformed BSON data containing a truncated regular-expression element without a trailing NUL byte. This can cause the application to crash if the C extension is loaded and the BSON is passed to the decode or decode_all API.

Detection Guidance

This vulnerability can be detected by checking if the MongoDB Python Driver is using the binary accelerator feature and if malformed BSON data is being processed. Monitor for application crashes when decoding BSON data, especially regular-expression elements without trailing NUL bytes. Ensure the driver version is updated to a patched release.

Impact Analysis

An attacker who can provide malformed BSON data to the application could cause it to terminate unexpectedly. This may lead to denial of service if the application crashes during normal operations.

Compliance Impact

This vulnerability causes an application process to terminate when decoding malformed BSON data, which could lead to denial of service. While it does not directly impact data confidentiality or integrity, availability issues may affect compliance with standards like GDPR or HIPAA that require timely access to personal or health data.

Mitigation Strategies

Update the MongoDB Python Driver to the latest version that patches this vulnerability. Avoid using the binary accelerator for decoding BSON data and ensure all BSON inputs are validated before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106435. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart