CVE-2018-16790: MongoDB Libbson
High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
Affected products
- MongoDB Libbson: version 1.12.0 only
Published 2018-09-10. Last modified 2026-06-17.