CVE-2026-106435: Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python Driver

Published Oct 8, 2026
·
Updated

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decodeall API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.

Affected Software

1 affected component
pypi/pymongo

Event History

Oct 8, 2026
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are realistically exposed to this denial-of-service condition?

Applications are exposed if they pass attacker-controlled or otherwise malformed BSON to the documented decode or decode_all API while the MongoDB Python Driver's C extension is loaded. The normal database wire-protocol path does not reach the affected code.

2

What must an attacker provide to trigger the issue?

An attacker must be able to supply malformed BSON containing a truncated regular-expression element with no trailing NUL byte to an application that decodes it through decode or decode_all. Exploitation causes the application process to terminate.

3

Is a default database connection workflow affected?

No. The driver's normal database wire-protocol processing does not reach the vulnerable decoding path; exposure depends on an application explicitly decoding supplied BSON through the documented APIs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203