Buffer-Reservation API Vulnerability in MongoDB C Driver
CVE-2026-106437

5.9MEDIUM

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-106437?

The BSON buffer-reservation API within the MongoDB C Driver contains a flaw that permits the recording of a length smaller than the minimum five-byte BSON standard. This issue can result in unsigned length calculations underflowing, potentially allowing later operations to read from or write to areas outside of the intended document buffer. If an attacker can influence the length parameter supplied by the embedding application, they may cause the application to crash or corrupt adjacent memory. To exploit this vulnerability, an application must pass an incorrect undersized value to the bson_reserve_buffer function, followed by executing an impacted operation. For more details, refer to the related issue on MongoDB's JIRA page.

Affected Version(s)

C Driver 1.4.0 < 1.30.13

C Driver 2.0.0 < 2.5.6

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.