CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106435

MEDIUMCVSS 5.1NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-106435 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106435

MEDIUMCVSS 5.1NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]