BSON Array Length Validation Issue in MongoDB Go Driver
CVE-2026-107325

8.2HIGH

Key Information:

Vendor

Mongodb

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107325?

The MongoDB Go Driver is exposed to a vulnerability due to improper validation of BSON array lengths. This issue occurs when an application processes malformed four-byte BSON arrays using methods like bson.RawArray.Validate or bsoncore.Array.Validate. An attacker with the ability to provide raw BSON array data may exploit this flaw to trigger an out-of-bounds index, leading to a runtime panic and potentially causing a denial of service by terminating the affected application process. While the vulnerability does not compromise data confidentiality or integrity, it poses a significant risk of application instability.

Affected Version(s)

Go Driver 1.1.0 <= 1.17.10

Go Driver 2.0.0 < 2.9.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.