CVE-2026-106437
Awaiting Analysis Awaiting Analysis - Queue

BSON Length Underflow in MongoDB C Driver

Vulnerability report for CVE-2026-106437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. An actor who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. Reaching this issue requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
MongoDB C Driver 1.4.0
MongoDB C Driver 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The BSON buffer-reservation API in the MongoDB C Driver has a flaw where it can record a length smaller than the minimum required five bytes for BSON documents. This leads to underflow in unsigned length calculations during append or comparison operations, causing the application to read or write outside the intended buffer. An attacker who controls the length value passed to bson_reserve_buffer can trigger crashes or memory corruption in the affected process.

Detection Guidance

This vulnerability requires checking the MongoDB C Driver version and inspecting application code for improper use of the BSON buffer-reservation API. Review if the application passes undersized values to bson_reserve_buffer and then performs append or comparison operations. No direct network detection commands are provided in the context.

Impact Analysis

This vulnerability can cause your application to crash or corrupt adjacent memory, potentially leading to denial of service or unauthorized data access. If exploited, it may allow attackers to execute arbitrary code or escalate privileges in the context of the vulnerable process.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling memory corruption or unauthorized data access. If exploited, it may lead to data breaches, unauthorized data exposure, or integrity violations, which are critical concerns under these regulations.

Mitigation Strategies

Update the MongoDB C Driver to the latest version that fixes the BSON buffer-reservation API issue. Review applications using the driver to ensure they do not pass undersized values to bson_reserve_buffer.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart