Impact
The vulnerability stems from a missing check on the length of a BSON array when using the Go driver. The driver’s Validate functions can read past the array’s bounds and trigger a runtime panic, terminating the application. An attacker can supply a crafted four‑byte array that forces this panic. The effect is a denial of service; the exploit does not expose or modify data.
Affected Systems
Impacted product is the MongoDB Go Driver. No specific version range is provided in the advisory. Applications that import and use the driver, particularly those calling bson.RawArray.Validate or bsoncore.Array.Validate, are at risk.
Risk and Exploitability
The CVSS score of 8.2 classifies this as high severity. EPSS data is not available, and it is not listed in CISA KEV, implying no known active exploits at the time of this analysis. The attack requires the ability to deliver raw BSON array data to the application, which is possible if the application accepts untrusted data from clients, networks, or files; authentication is not needed. If such data can reach the driver, an attacker can reliably crash the process, causing service interruption.
OpenCVE Enrichment