PT-2026-98233 · Mongodb · Mongo-Python-Driver

CVE-2026-96749

·

Published

2026-09-24

·

Updated

2026-10-05

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Python Driver (affected versions not specified)
Description An integer overflow exists in the BSON document encoding component of the bundled native extension. This occurs when a single document is constructed using an excessively large amount of caller-supplied data. The issue stems from size arithmetic being performed using a signed 32-bit type and a guard mechanism that exhibits undefined behavior according to the C language standard. An unprivileged attacker who can provide a very large value for encoding may cause a write operation outside the bounds of an allocated buffer within the application process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105110
CVE-2026-96749
GHSA-V4X9-3549-CRWV
OPENSUSE-SU-2026:11935-1
OPENSUSE-SU-2026:22003-1
SUSE-SU-2026:4398-1

Affected Products

Mongo-Python-Driver