Description
An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Heap Corruption and Process Termination
Action: Patch
AI Analysis

Impact

An off‑by‑one error in the BSON bulk document writer of the MongoDB C Driver causes a single zero byte to be written past the end of a heap allocation when a document ends precisely at a buffer boundary. This write can corrupt adjacent memory or terminate the process. The flaw is not a direct code‑execution vector, but it can lead to unintended data corruption or denial of service if an attacker can influence the size of the documents serialized by the embedding application. The impact is therefore memory corruption that may culminate in application crashes or instability.

Affected Systems

The vulnerability affects the MongoDB C Driver. No specific version range is listed in the CVE data, so any deployment that has not applied the latest fix is potentially impacted.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. EPSS is not available, and the issue is not currently listed in the CISA KEV catalog, suggesting low or uncertain exploitation probability. The exploitation path requires the application to use the BSON bulk‑writer API and construct documents that cumulatively reach the critical boundary size. Without such a precise payload, the vulnerability is unlikely to be leveraged, but it remains a risk for applications that meet the stated conditions.

Generated by OpenCVE AI on October 8, 2026 at 20:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB C Driver to the latest patched release that corrects the off‑by‑one write
  • If an immediate upgrade is not feasible, modify the application to avoid using the BSON bulk writer API or enforce strict size limits that prevent the boundary condition from being met
  • Implement runtime safeguards such as memory corruption detection, canaries, or fuzzing to monitor for and mitigate accidental memory writes, and watch for abnormal process termination events

Generated by OpenCVE AI on October 8, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.
Title One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:19:51.552Z

Reserved: 2026-10-06T16:40:35.016Z

Link: CVE-2026-106431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:59.070

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:15:18Z

Weaknesses