Off-by-One Error in MongoDB C Driver Exploits Buffer Vulnerability
CVE-2026-106431

5.9MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-106431?

A critical vulnerability exists in the MongoDB C Driver due to an off-by-one error in the BSON bulk document writer. This flaw allows for the potential writing of a zero byte immediately beyond allocated heap memory when a document concludes at a specific buffer boundary. Exploitations can occur if an attacker influences the size of the serialized documents, causing memory corruption or potentially terminating the application process. To be vulnerable, the application must utilize the BSON bulk-writer API and produce an exact total document size.

Affected Version(s)

C Driver 0.5.0 < 1.30.13

C Driver 2.0.0 < 2.5.6

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.