CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder
Vulnerability ID: CVE-2026-96749
CVSS Score: 8.4
Published: 2026-10-05
An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.
TL;DR
Compiler optimization of undefined signed integer overflow checks in PyMongo's native BSON encoder leads to heap-based buffer overflow when serializing objects larger than 2GiB.
Technical Details
- CWE ID: CWE-190 (Integer Overflow or Wraparound), CWE-122 (Heap-based Buffer Overflow)
- Attack Vector: Local (Elevated to Remote if exposing serialization endpoints)
- CVSS v3.1 Score: 8.4 (High Severity)
- CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS Score: 0.00132 (0.13% probability of exploitation)
- Exploit Status: None (No public exploits or wild-exploitation documented)
- CISA KEV Status: Not Listed
Affected Systems
- Applications running on 64-bit architectures using PyMongo with native C extensions enabled.
-
PyMongo: >= 1.9.0, < 4.18.2 (Fixed in:
4.18.2)
Code Analysis
Commit: 6ab44be
PYTHON-5996 Harden bson buffer size guard against signed integer overflow
Mitigation Strategies
- Upgrade PyMongo to version 4.18.2 or higher.
- Disable PyMongo native C extensions by setting the environment variable PYTHON_BSON_EXTENSIONS=0.
- Implement application-level input size limits to reject payloads approaching MongoDB's 16MB maximum document size.
Remediation Steps:
- Verify the installed PyMongo package version using 'pip show pymongo'.
- Execute 'pip install --upgrade pymongo>=4.18.2' to apply the official security patch.
- If upgrading is not possible, append 'export PYTHON_BSON_EXTENSIONS=0' to the environment profiles of your runtime systems.
- Introduce validation logic at input gateways to intercept and drop JSON/BSON structures that exceed defined size thresholds.
References
- GitHub Security Advisory GHSA-v4x9-3549-crwv
- NVD CVE-2026-96749 Analysis
- PyMongo Bug Merge Commit
- PyMongo Fix Commit
- PyMongo Pull Request 3066
- PyMongo Release 4.18.2
- PyMongo 4.18.2 Changelog
- CVE-2026-96749 Record
- Wiz Vulnerability Analysis Data
Read the full report for CVE-2026-96749 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)