MongoDB Python 驱动程序的二进制加速器在解码包含截断正则表达式元素且缺少末尾 NUL 字节的畸形 BSON 数据时,可能会出现缓冲区外读取的情况。攻击者若能够向文档中描述的 或 API 提供恶意构造的 BSON 数据,并且在加载了 C 扩展的情况下,可能导致应用程序进程终止。需要注意的是,驱动程序的正常数据库 Wire 协议路径不会执行到此段问题代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Python Driver | 0.10.3 ~ 4.18.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106433 | 8.8 HIGH | Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt |
| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107325 | 5.9 MEDIUM | Application denial of service via missing BSON array length validation in MongoDB Go Drive |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106436 | 4.8 MEDIUM | Application denial of service and data truncation via unchecked BSON append failures in Mo |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106438 | 4.0 MEDIUM | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
| CVE-2026-106432 | 3.6 LOW | Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver |
No comments yet