CVE-2026-106435: Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python Driver
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decodeall API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
Affected Software
Event History
Frequently Asked Questions
Which applications are realistically exposed to this denial-of-service condition?
Applications are exposed if they pass attacker-controlled or otherwise malformed BSON to the documented decode or decode_all API while the MongoDB Python Driver's C extension is loaded. The normal database wire-protocol path does not reach the affected code.
What must an attacker provide to trigger the issue?
An attacker must be able to supply malformed BSON containing a truncated regular-expression element with no trailing NUL byte to an application that decodes it through decode or decode_all. Exploitation causes the application process to terminate.
Is a default database connection workflow affected?
No. The driver's normal database wire-protocol processing does not reach the vulnerable decoding path; exposure depends on an application explicitly decoding supplied BSON through the documented APIs.