CVE-2026-106435: medium-severity vulnerability in MongoDB Python Driver
Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python Driver
Published
10Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9
exploitation probability
—
observed exploitation
nono source reports it
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
MongoDB · Python DriverRelated CVEs — MongoDB Python Driver
In the same product, most dangerous first.
CVE-2026-88029MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python DriverEPSS 0.3%CVE-2026-96748HIGHConnection redirection via percent-encoded delimiter injection in connection string hostsEPSS 0.3%CVE-2026-96749HIGHHeap out-of-bounds write via signed size overflow in BSON document encodingEPSS 0.1%CVE-2026-96747MEDIUMForced local Unix socket connection via dot-sock KMS endpoint in client-side field encryptionEPSS 0.1%