Description
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size) before using it in an array index calculation. When the length field is zero, the expression used to check the document's null terminator wraps to UINT32_MAX, causing a heap out-of-bounds read that crashes the process. An unauthorized party who can supply crafted BSON input to an application using this API can cause a denial of service.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via heap out‑of‑bounds read
Action: Apply Patch
AI Analysis

Impact

A missing lower‑bound check in libbson’s bson_new_from_buffer() lets an attacker supply a zero‑length BSON prefix. The function reads a 32‑bit length field without ensuring it is at least the minimum BSON size of five bytes, causing an integer underflow. This underflow causes the null‑terminator test to wrap to UINT32_MAX and results in a heap out‑of‑bounds read that crashes the process, creating a denial of service condition.

Affected Systems

MongoDB Inc. C Driver is affected. Specific version information is not provided in the advisory, so any deployment using the vulnerable libbson component is potentially impacted until a patched build is applied.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity. The EPSS score is represented as less than 1%, which denotes a very low, but non‑zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. If an application can receive uncontrolled BSON data from an external source, an attacker could construct a payload with a zero‑length prefix and trigger the crash. The attack vector is inferred to be through untrusted input to the API, potentially enabling remote denial of service if the target processes external data.

Generated by OpenCVE AI on September 18, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB C Driver to the latest version that includes the libbson patch.
  • If an immediate upgrade is not feasible, validate the BSON document length before calling bson_new_from_buffer by checking that it is at least five bytes and rejecting or handling smaller values appropriately.
  • Limit exposure of the bson_new_from_buffer API to trusted data only or otherwise enforce input origin controls to prevent untrusted BSON from reaching the vulnerable function.

Generated by OpenCVE AI on September 18, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:c_driver:*:*:*:*:*:mongodb:*:*

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb c Driver
Vendors & Products Mongodb
Mongodb c Driver

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size) before using it in an array index calculation. When the length field is zero, the expression used to check the document's null terminator wraps to UINT32_MAX, causing a heap out-of-bounds read that crashes the process. An unauthorized party who can supply crafted BSON input to an application using this API can cause a denial of service.
Title Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb C Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-18T14:31:41.359Z

Reserved: 2026-09-17T20:11:01.369Z

Link: CVE-2026-93395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:56.443

Modified: 2026-09-25T20:32:52.170

Link: CVE-2026-93395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)