Buffer Overflow in MongoDB Python Driver Affects Wide Range of Applications
CVE-2026-106435

5.9MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 October 2026

What is CVE-2026-106435?

The MongoDB Python Driver contains a vulnerability within its binary accelerator component that allows it to read data outside of allocated buffers. This issue arises when an application attempts to decode malformed BSON data that includes a truncated regular-expression element missing a trailing NUL byte. If an attacker can provide such malformed BSON to the decode or decode_all API, it may result in the termination of the application process when the C extension is in use. However, it is important to note that the normal database wire-protocol operations do not invoke this vulnerable code path.

Affected Version(s)

Python Driver 0.10.3 <= 4.18.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.