PT-2026-98233 · Mongodb · Mongo-Python-Driver
CVE-2026-96749
·
Published
2026-09-24
·
Updated
2026-10-05
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB Python Driver (affected versions not specified)
Description
An integer overflow exists in the BSON document encoding component of the bundled native extension. This occurs when a single document is constructed using an excessively large amount of caller-supplied data. The issue stems from size arithmetic being performed using a signed 32-bit type and a guard mechanism that exhibits undefined behavior according to the C language standard. An unprivileged attacker who can provide a very large value for encoding may cause a write operation outside the bounds of an allocated buffer within the application process.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongo-Python-Driver