CVE-2026-107324: MongoDB Go Driver

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.

Affected products

  • MongoDB Go Driver: from 1.0.0, before 1.2.0 (fixed in 1.2.0); from 2.0.0, before 2.9.0 (fixed in 2.9.0)

Published 2026-10-08. Last modified 2026-10-08.