Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
Medium6.3CVE-2026-84963 · Published Sep 3, 2026
### Impact An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data. ### Patches Fixed in 1.30.9 and 2.5.2 ### Workarounds Validate length of inputs before processing JSON. ### References https://jira.mongodb.org/browse/CDRIVER-6407
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MongoDB C Driver Product | >= 1.10.0, < 1.30.9 | 1.30.9 |
| >= 2.0.0, < 2.5.2 | 2.5.2 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
More MongoDB advisories
All MongoDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | Authenticated KMS request forgery via CRLF injection in GCP key identifier strings | Medium5.7 | 1.20.2 |
| Sep 3 | Heap out-of-bounds read via corrupt nested BSON in field path error message | Medium6.9 | 1.21.8+2 more |
| Sep 3 | Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path | High7.1 | 1.20.4 |
| Sep 3 | BSON element injection via NUL-embedded document keys in builder append | Medium5.9 | 4.5.2 |
| Sep 3 | Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser | Medium5.9 | 4.5.2 |
| Sep 3 | Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output | Medium6.3 | 1.30.9+1 more |