CVE-2026-107324: MongoDB Go Driver
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who can supply BSON bytes to an affected application may terminate an unprotected application process, causing a denial of service. The driver's server-monitoring path contains panic recovery and is limited to server-selection failure.
Affected products
- MongoDB Go Driver: from 1.0.0, before 1.2.0 (fixed in 1.2.0); from 2.0.0, before 2.9.0 (fixed in 2.9.0)
Published 2026-10-08. Last modified 2026-10-08.