DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-96749: CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

Vulnerability ID: CVE-2026-96749
CVSS Score: 8.4
Published: 2026-10-05

An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.

TL;DR

Compiler optimization of undefined signed integer overflow checks in PyMongo's native BSON encoder leads to heap-based buffer overflow when serializing objects larger than 2GiB.


Technical Details

  • CWE ID: CWE-190 (Integer Overflow or Wraparound), CWE-122 (Heap-based Buffer Overflow)
  • Attack Vector: Local (Elevated to Remote if exposing serialization endpoints)
  • CVSS v3.1 Score: 8.4 (High Severity)
  • CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • EPSS Score: 0.00132 (0.13% probability of exploitation)
  • Exploit Status: None (No public exploits or wild-exploitation documented)
  • CISA KEV Status: Not Listed

Affected Systems

  • Applications running on 64-bit architectures using PyMongo with native C extensions enabled.
  • PyMongo: >= 1.9.0, < 4.18.2 (Fixed in: 4.18.2)

Code Analysis

Commit: 6ab44be

PYTHON-5996 Harden bson buffer size guard against signed integer overflow

Mitigation Strategies

  • Upgrade PyMongo to version 4.18.2 or higher.
  • Disable PyMongo native C extensions by setting the environment variable PYTHON_BSON_EXTENSIONS=0.
  • Implement application-level input size limits to reject payloads approaching MongoDB's 16MB maximum document size.

Remediation Steps:

  1. Verify the installed PyMongo package version using 'pip show pymongo'.
  2. Execute 'pip install --upgrade pymongo>=4.18.2' to apply the official security patch.
  3. If upgrading is not possible, append 'export PYTHON_BSON_EXTENSIONS=0' to the environment profiles of your runtime systems.
  4. Introduce validation logic at input gateways to intercept and drop JSON/BSON structures that exceed defined size thresholds.

References


Read the full report for CVE-2026-96749 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)