Threat Advisory

PyMongo Heap Out-of-Bounds Write via Signed Size Overflow in BSON Document Encoding

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-96749 is a high-severity vulnerability with a CVSS score of 8.4 that affects the MongoDB Python Driver's bundled native extension, specifically the BSON document encoding component. The issue arises from an integer overflow in size arithmetic performed in a signed 32-bit type, which can lead to a write outside the bounds of an allocated buffer inside the application's own process. This vulnerability is exploitable via local attack vectors and requires no privileges, allowing an attacker with access to data that an application encodes to potentially cause a heap out-of-bounds write. The business impact of this flaw is significant, as it can lead to arbitrary code execution and compromise the confidentiality, integrity, and availability of sensitive data in affected versions prior to 4.18.2.

RECOMMENDATION:

We recommend you to update PyMongo to version 4.18.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-96749 is a high-severity vulnerability with a CVSS score of 8.4 that affects the MongoDB Python Driver's bundled native extension, specifically the BSON document encoding component. The issue arises from an integer overflow in size arithmetic performed in a signed 32-bit type, which can lead to a write outside the bounds of an allocated buffer inside the application's own process. This vulnerability is exploitable via local attack vectors and requires no privileges, allowing an attacker with access to data that an application encodes to potentially cause a heap out-of-bounds write. The business impact of this flaw is significant, as it can lead to arbitrary code execution and compromise the confidentiality, integrity, and availability of sensitive data in affected versions prior to 4.18.2.

RECOMMENDATION:

We recommend you to update PyMongo to version 4.18.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu