CVE-2024-6381: MongoDB Libbson

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

Affected products

  • MongoDB Libbson: before 1.26.2 (fixed in 1.26.2)

Published 2024-07-02. Last modified 2026-06-17.