BSON element injection via NUL-embedded document keys in builder append
Medium5.9CVE-2026-84966 · Published Sep 3, 2026
### Impact An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate the calling process. No authentication is required, but the calling application must pass the oversized name in a specific form. ### Patches Fixed in 4.5.2. ### Workarounds Validate keys before appending. ### References https://jira.mongodb.org/browse/CXX-3548
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MongoDB C++ Driver Product | >= 3.2.0, < 4.5.2 | 4.5.2 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | Authenticated KMS request forgery via CRLF injection in GCP key identifier strings | Medium5.7 | 1.20.2 |
| Sep 3 | Heap out-of-bounds read via corrupt nested BSON in field path error message | Medium6.9 | 1.21.8+2 more |
| Sep 3 | Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path | High7.1 | 1.20.4 |
| Sep 3 | Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser | Medium5.9 | 4.5.2 |
| Sep 3 | Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output | Medium6.3 | 1.30.9+1 more |
| Sep 3 | MongoDB for VS Code: command injection | Medium5.1 | 1.17.1 |