CVE-2026-107325: MongoDB Go Driver

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.

Affected products

  • MongoDB Go Driver: from 1.1.0, up to and including 1.17.10; from 2.0.0, before 2.9.2 (fixed in 2.9.2)

Published 2026-10-08. Last modified 2026-10-08.