{"id":"CVE-2026-81521","title":"The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation","summary":"The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. A…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-99"],"vendor":"mongodb","product":"go_driver","affected":["go_driver >= 2.1.0, < 2.8.2"],"patched":["go_driver 2.8.2"],"published":"2026-08-27","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:17:28.347","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81521","references":[{"url":"https://jira.mongodb.org/browse/GODRIVER-4075","label":"cna@mongodb.com"},{"url":"https://pkg.go.dev/go.mongodb.org/mongo-driver/v2@v2.8.2","label":"cna@mongodb.com"}],"tags":["nvd"],"epss":0.00349,"epssPercentile":0.25941,"ingestedAt":"2026-09-29T19:44:04.116Z","slug":"CVE-2026-81521","body":"## Overview\n\nThe MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.\n\n## Affected\n\n- `go_driver >= 2.1.0, < 2.8.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `go_driver 2.8.2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}