CVE-2026-107325Medium· 5.9▾ SunlitImproper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthe…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-2008High· 8.2A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler
CVE-2026-103220Medium· 4.5The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untruste…
CVE-2026-107737NoneSumatraPDF is a multi-format reader for Windows
CVE-2026-107222Medium· 6.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
CVE-2026-107225Medium· 6.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
CVE-2026-107218Medium· 5.3Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets