Description
The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. An actor who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. Reaching this issue requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Memory corruption causing potential denial of service and information disclosure
Action: Apply Patch
AI Analysis

Impact

The BSON buffer-reservation API in the MongoDB C Driver reserves memory based on a length supplied by applications. The API accepts lengths smaller than the five-byte BSON minimum. Subsequent append or comparison operations perform unsigned length calculations that underflow when the reserved length is undersized, allowing reads or writes beyond the intended document buffer. An actor who can influence the length passed to bson_reserve_buffer can cause the driver, and consequently the hosting application, to terminate or corrupt adjacent memory. This can lead to a denial‑of‑service condition and could leak or overwrite data in nearby memory, potentially exposing sensitive information or altering program state.

Affected Systems

The vulnerability affects MongoDB's official C Driver. Specific product versions are not listed in the advisory; however, any installation of the C Driver that uses the bson_reserve_buffer function without input validation is susceptible.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV catalog, suggesting no known active exploitation. Exploitation would require an application capable of supplying an undersized length argument to bson_reserve_buffer followed by an append or comparison operation, implying a local or embedded attacker with control over driver usage. The risk thus depends on the attack surface of the application and whether it receives untrusted input that could influence the buffer‑reservation length.

Generated by OpenCVE AI on October 8, 2026 at 20:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of the MongoDB C Driver that removes the undersized buffer reservation bug.
  • Ensure that the application never passes a length smaller than the BSON minimum of five bytes to bson_reserve_buffer; add input validation or bounds checking before calling the function.
  • If an upgrade is not immediately possible, add defensive checks around bson_reserve_buffer calls to detect and reject undersized lengths, or replace the function with a safer implementation that enforces the minimum size.

Generated by OpenCVE AI on October 8, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. An actor who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. Reaching this issue requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation.
Title Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:20:23.562Z

Reserved: 2026-10-06T16:40:35.017Z

Link: CVE-2026-106437

cve-icon Vulnrichment

Updated: 2026-10-08T19:20:19.412Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:16:59.550

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)