CVE-2026-106435
EUVD-2026-9525408.10.2026, 21:17
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | python_driver | 0.10.3 ≤ 𝑥 ≤ 4.18.2 | CNA |
Common Weakness Enumeration