CVE-2026-106435: MongoDB Python Driver

Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.

Affected products

  • MongoDB Python Driver: from 0.10.3, up to and including 4.18.2

Published 2026-10-08. Last modified 2026-10-09.