{"id":"CVE-2026-106435","title":"The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte","summary":"The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the docume…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"published":"2026-10-08","updated":"2026-10-09","sourceUpdated":"2026-10-09T12:17:07.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106435","references":[{"url":"https://jira.mongodb.org/browse/PYTHON-6110","label":"cna@mongodb.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T22:11:53.856Z","slug":"CVE-2026-106435","body":"## Overview\n\nThe MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}