CVE-2026-107324: Application denial of service via integer overflow in BSON value-length validation in MongoDB Go Driver

Published Oct 8, 2026
·
Updated

An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.

Affected Software

1 affected component
MongoDB Go Driver

Event History

Oct 8, 2026
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using the MongoDB Go Driver are exposed if an unauthenticated actor can supply malformed BSON bytes that the application validates or accesses. The available information does not identify affected or fixed driver versions.

2

What does an attacker need to exploit the vulnerability?

The attacker needs a way to provide malformed BSON data to the affected application. No authentication or user interaction is required, but exploitation has high attack complexity.

3

What is the expected impact of a successful exploit?

Malformed BSON can trigger a runtime panic and terminate an application process that lacks panic protection, causing denial of service. The provided impact information indicates no confidentiality or integrity impact.

4

Does the driver's server-monitoring path prevent the application from crashing?

The server-monitoring path has panic recovery, but its effect is limited to server-selection failure. This does not provide general protection for application paths that validate or access attacker-supplied BSON.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203