CVE-2018-16790: MongoDB Libbson

High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

Affected products

  • MongoDB Libbson: version 1.12.0 only

Published 2018-09-10. Last modified 2026-06-17.