CVE-2026-107324: Application denial of service via integer overflow in BSON value-length validation in MongoDB Go Driver
An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.
Affected Software
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using the MongoDB Go Driver are exposed if an unauthenticated actor can supply malformed BSON bytes that the application validates or accesses. The available information does not identify affected or fixed driver versions.
What does an attacker need to exploit the vulnerability?
The attacker needs a way to provide malformed BSON data to the affected application. No authentication or user interaction is required, but exploitation has high attack complexity.
What is the expected impact of a successful exploit?
Malformed BSON can trigger a runtime panic and terminate an application process that lacks panic protection, causing denial of service. The provided impact information indicates no confidentiality or integrity impact.
Does the driver's server-monitoring path prevent the application from crashing?
The server-monitoring path has panic recovery, but its effect is limited to server-selection failure. This does not provide general protection for application paths that validate or access attacker-supplied BSON.