An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3832-1 | pymongo security update |
![]() |
DLA-3889-1 | pymongo security update |
![]() |
EUVD-2024-2101 | An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory. |
![]() |
GHSA-m87m-mmvp-v9qm | PyMongo Out-of-bounds Read in the bson module |
![]() |
USN-6904-1 | PyMongo vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 06 Jun 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:8 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
Fri, 14 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2025-02-13T17:54:22.106Z
Reserved: 2024-06-04T13:49:31.496Z
Link: CVE-2024-5629

Updated: 2024-09-16T23:02:28.936Z

Status : Modified
Published: 2024-06-05T15:15:12.737
Modified: 2024-11-21T09:48:02.860
Link: CVE-2024-5629


No data.