Impact
The vulnerability occurs in the MongoDB Python Driver’s binary accelerator when decoding malformed BSON that contains a truncated regular‑expression element missing its trailing NUL byte. During decoding the driver performs an out‑of‑bounds read and can terminate the application process that loaded the C extension. The result is a denial‑of‑service for that process, but no direct confidentiality or integrity impact is described.
Affected Systems
Vendor: MongoDB, Product: Python Driver. Specific affected versions are not listed in the available data, so all releases of the driver that include the binary accelerator are potentially impacted until an official patch is released.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate severity. No EPSS score is currently published, and the vulnerability is not listed in CISA KEV. An attacker who can supply BSON to the documented decode or decode_all API can trigger the crash; this typically requires either local privilege or an application that accepts user‑supplied BSON. The risk is that the affected application may become unavailable, potentially impacting availability for services depending on the driver.
OpenCVE Enrichment