BSON Array Length Validation Issue in MongoDB Go Driver
CVE-2026-107325
8.2HIGH
What is CVE-2026-107325?
The MongoDB Go Driver is exposed to a vulnerability due to improper validation of BSON array lengths. This issue occurs when an application processes malformed four-byte BSON arrays using methods like bson.RawArray.Validate or bsoncore.Array.Validate. An attacker with the ability to provide raw BSON array data may exploit this flaw to trigger an out-of-bounds index, leading to a runtime panic and potentially causing a denial of service by terminating the affected application process. While the vulnerability does not compromise data confidentiality or integrity, it poses a significant risk of application instability.
Affected Version(s)
Go Driver 1.1.0 <= 1.17.10
Go Driver 2.0.0 < 2.9.2