Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/PYTHON-6110 |
|
Thu, 08 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb python Driver |
|
| Vendors & Products |
Mongodb
Mongodb python Driver |
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code. | |
| Title | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python Driver | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-10-08T20:12:15.074Z
Reserved: 2026-10-06T16:40:35.017Z
Link: CVE-2026-106435
No data.
Status : Awaiting Analysis
Published: 2026-10-08T21:17:51.667
Modified: 2026-10-08T21:33:42.423
Link: CVE-2026-106435
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:30:18Z