CVE-2020-12135: MongoDB C Driver
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
Affected products
- MongoDB C Driver: before 0.8 (fixed in 0.8)
- Whoopsie Project Whoopsie: up to and including 0.2.69
Published 2020-04-24. Last modified 2026-06-17.