Description
Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.
Published: 2026-10-08
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability stems from a missing check on the length of a BSON array when using the Go driver. The driver’s Validate functions can read past the array’s bounds and trigger a runtime panic, terminating the application. An attacker can supply a crafted four‑byte array that forces this panic. The effect is a denial of service; the exploit does not expose or modify data.

Affected Systems

Impacted product is the MongoDB Go Driver. No specific version range is provided in the advisory. Applications that import and use the driver, particularly those calling bson.RawArray.Validate or bsoncore.Array.Validate, are at risk.

Risk and Exploitability

The CVSS score of 8.2 classifies this as high severity. EPSS data is not available, and it is not listed in CISA KEV, implying no known active exploits at the time of this analysis. The attack requires the ability to deliver raw BSON array data to the application, which is possible if the application accepts untrusted data from clients, networks, or files; authentication is not needed. If such data can reach the driver, an attacker can reliably crash the process, causing service interruption.

Generated by OpenCVE AI on October 8, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB Go Driver to the latest released version that contains the fix for the array length validation issue.
  • If an upgrade is not feasible, replace or wrap calls to bson.RawArray.Validate and bsoncore.Array.Validate with stricter input validation that ensures the array length is within acceptable limits before validation.
  • Configure network or application interfaces to reject or sanitize raw BSON data from untrusted origins to prevent malicious input from reaching the driver.

Generated by OpenCVE AI on October 8, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb go Driver
Vendors & Products Mongodb
Mongodb go Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.
Title Application denial of service via missing BSON array length validation in MongoDB Go Driver
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Go Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:32:32.402Z

Reserved: 2026-10-07T17:54:29.794Z

Link: CVE-2026-107325

cve-icon Vulnrichment

Updated: 2026-10-08T19:32:29.237Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:00.173

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-107325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:11Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index