MongoDB Python 驱动程序的捆绑原生扩展中的 BSON 文档编码组件存在整数溢出漏洞。当使用用户提供的异常大量的数据构建单个文档时,可能会发生该漏洞。大小计算使用有符号 32 位类型进行,而用于检测溢出的保护机制的代码形式不符合 C 语言标准定义的行为。攻击者无需任何特权,只需能在应用程序编码的数据中注入一个极大值,便可能在特定情况下(取决于原生扩展的构建方式)导致应用程序进程内部向已分配缓冲区边界之外进行内存写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Python Driver | 1.9.0 ~ 4.18.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96750 | 7.1 HIGH | Shell script injection via server-supplied database name in Open MongoDB shell |
| CVE-2026-96744 | 7.1 HIGH | Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB |
| CVE-2026-96746 | 6.5 MEDIUM | Heap buffer overflow via mid-scan command list growth in client topology monitoring |
| CVE-2026-96748 | 6.5 MEDIUM | Connection redirection via percent-encoded delimiter injection in connection string hosts |
| CVE-2026-96745 | 5.6 MEDIUM | PHP object injection via unsuppressible __pclass class inference in command monitoring eve |
| CVE-2026-96747 | 5.0 MEDIUM | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt |
No comments yet