CVE-2026-107325
Awaiting Analysis Awaiting Analysis - Queue

Improper BSON Array Validation in MongoDB Go Driver

Vulnerability report for CVE-2026-107325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
MongoDB Go Driver 1.1.0
MongoDB Go Driver 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper validation of a BSON array length in the MongoDB Go Driver. When a malformed four-byte array is processed by bson.RawArray.Validate or bsoncore.Array.Validate, it can cause an out-of-bounds index and trigger a runtime panic. This leads to an application crash, resulting in a denial of service.

Detection Guidance

This vulnerability involves improper validation of BSON arrays in the MongoDB Go Driver. Detection requires checking for applications using vulnerable versions of the driver and monitoring for runtime panics or crashes when processing BSON data. No specific commands are provided in the context.

Impact Analysis

An unauthenticated attacker can supply malicious BSON array data to crash the affected application. This causes an unprotected process to terminate, leading to service disruption. No data theft or modification is possible, but availability is compromised.

Compliance Impact

This vulnerability primarily impacts availability, which may violate compliance requirements for uptime and reliability in GDPR, HIPAA, and other standards. However, no confidentiality or integrity impact is identified, so data protection compliance is not directly affected.

Mitigation Strategies

Update the MongoDB Go Driver to the latest patched version. Ensure applications validate BSON input before processing. Monitor for crashes or panics in applications handling BSON data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart