CVE-2026-107324
EUVD-2026-9516508.10.2026, 19:17
An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | go_driver | 1.0.0 ≤ 𝑥 < 1.2.0 | CNA |
| mongodb | go_driver | 2.0.0 ≤ 𝑥 < 2.9.0 | CNA |