CVE-2026-106435: MongoDB Python Driver
Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.
The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documented decode or decode_all API can cause the application process to terminate when the C extension is loaded. The driver's normal database wire-protocol path does not reach this code.
Affected products
- MongoDB Python Driver: from 0.10.3, up to and including 4.18.2
Published 2026-10-08. Last modified 2026-10-09.