Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96749— Heap out-of-bounds write via signed size overflow in BSON document encoding

Quick assessment

Affected
MongoDB Python Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB Python 驱动程序的捆绑原生扩展中的 BSON 文档编码组件存在整数溢出漏洞。当使用用户提供的异常大量的数据构建单个文档时,可能会发生该漏洞。大小计算使用有符号 32 位类型进行,而用于检测溢出的保护机制的代码形式不符合 C 语言标准定义的行为。攻击者无需任何特权,只需能在应用程序编码的数据中注入一个极大值,便可能在特定情况下(取决于原生扩展的构建方式)导致应用程序进程内部向已分配缓冲区边界之外进行内存写入。

CVSS 8.4 · High EPSS 0.13% · P2
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96749

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap out-of-bounds write via signed size overflow in BSON document encoding
Source: CVE Program / CVE List V5
Vulnerability Description
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB Python Driver 1.9.0 ~ 4.18.2 -

II. Public POCs for CVE-2026-96749

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96749

请登录查看更多情报信息。

Other References for CVE-2026-96749 (3)

Same Patch Batch · MongoDB · 2026-09-24 · 7 CVEs total

CVE-2026-96750 7.1 HIGH Shell script injection via server-supplied database name in Open MongoDB shell
CVE-2026-96744 7.1 HIGH Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB
CVE-2026-96746 6.5 MEDIUM Heap buffer overflow via mid-scan command list growth in client topology monitoring
CVE-2026-96748 6.5 MEDIUM Connection redirection via percent-encoded delimiter injection in connection string hosts
CVE-2026-96745 5.6 MEDIUM PHP object injection via unsuppressible __pclass class inference in command monitoring eve
CVE-2026-96747 5.0 MEDIUM Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt

IV. Related Vulnerabilities

V. Comments for CVE-2026-96749

No comments yet


Leave a comment