CVE-2026-106435

Public on 2026-10-08
Modified on 2026-10-10
Description
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 python-pymongo Pending Fix
Amazon Linux 2027 Preview python-pymongo Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H