Skip to content
MongoDBGHSA-7xfm-q62h-hhjf

BSON element injection via NUL-embedded document keys in builder append

Medium5.9CVE-2026-84966 · Published Sep 3, 2026

### Impact An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate the calling process. No authentication is required, but the calling application must pass the oversized name in a specific form. ### Patches Fixed in 4.5.2. ### Workarounds Validate keys before appending. ### References https://jira.mongodb.org/browse/CXX-3548

GitHub advisory

Affected versions

PackageAffectedFixed in
MongoDB C++ Driver
Product
>= 3.2.0, < 4.5.24.5.2
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)

More MongoDB advisories

All MongoDB

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.