Numeric Conversion Vulnerability in MongoDB C Driver's BSON Library
CVE-2026-84963
6.3MEDIUM
What is CVE-2026-84963?
A flaw in the numeric conversion process within the JSON parsing component of the MongoDB C Driver's BSON library could lead to inconsistencies during data handling. This issue may result in unusually large text values being shortened or omitted without any errors reported during the operation. As a consequence, an unauthenticated user with the ability to input data could manipulate the application into handling incorrect data, raising concerns over data integrity and reliability.
Affected Version(s)
C Driver 1.10.0 < 1.30.9
C Driver 2.0.0 < 2.5.2