Description
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Driver
AI Analysis

Impact

The vulnerability occurs in the MongoDB Python Driver’s binary accelerator when decoding malformed BSON that contains a truncated regular‑expression element missing its trailing NUL byte. During decoding the driver performs an out‑of‑bounds read and can terminate the application process that loaded the C extension. The result is a denial‑of‑service for that process, but no direct confidentiality or integrity impact is described.

Affected Systems

Vendor: MongoDB, Product: Python Driver. Specific affected versions are not listed in the available data, so all releases of the driver that include the binary accelerator are potentially impacted until an official patch is released.

Risk and Exploitability

The CVSS score is 5.9, indicating a moderate severity. No EPSS score is currently published, and the vulnerability is not listed in CISA KEV. An attacker who can supply BSON to the documented decode or decode_all API can trigger the crash; this typically requires either local privilege or an application that accepts user‑supplied BSON. The risk is that the affected application may become unavailable, potentially impacting availability for services depending on the driver.

Generated by OpenCVE AI on October 8, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MongoDB Python Driver to the latest release that addresses the issue
  • Validate or sanitize all BSON input before passing it to the decode or decode_all functions to avoid malformed data
  • If an update is not possible, disable the binary accelerator by configuring the driver to use the pure‑Python implementation or restrict the application from loading the C extension until a patch is applied

Generated by OpenCVE AI on October 8, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb python Driver
Vendors & Products Mongodb
Mongodb python Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
Title Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python Driver
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Python Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T20:12:15.074Z

Reserved: 2026-10-06T16:40:35.017Z

Link: CVE-2026-106435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:17:51.667

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-106435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses