Impact
An off‑by‑one error in the BSON bulk document writer of the MongoDB C Driver causes a single zero byte to be written past the end of a heap allocation when a document ends precisely at a buffer boundary. This write can corrupt adjacent memory or terminate the process. The flaw is not a direct code‑execution vector, but it can lead to unintended data corruption or denial of service if an attacker can influence the size of the documents serialized by the embedding application. The impact is therefore memory corruption that may culminate in application crashes or instability.
Affected Systems
The vulnerability affects the MongoDB C Driver. No specific version range is listed in the CVE data, so any deployment that has not applied the latest fix is potentially impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS is not available, and the issue is not currently listed in the CISA KEV catalog, suggesting low or uncertain exploitation probability. The exploitation path requires the application to use the BSON bulk‑writer API and construct documents that cumulatively reach the critical boundary size. Without such a precise payload, the vulnerability is unlikely to be leveraged, but it remains a risk for applications that meet the stated conditions.
OpenCVE Enrichment