MongoDB Go Driver Bulk Write Operation Vulnerability
CVE-2026-81521
7.1HIGH
What is CVE-2026-81521?
The MongoDB Go Driver contains a vulnerability in its Client.BulkWrite API, which can be exploited if an application passes user-supplied database names that contain reserved separator characters. This flaw allows the construction of a target namespace that may not correspond to the intended database, potentially redirecting writes to unexpected locations. Developers must ensure that input validation and sanitization are thoroughly implemented to prevent untrusted inputs from compromising data integrity.
Affected Version(s)
GO Driver 2.1.0 < 2.8.2