CVE-2026-84965: MongoDB C Driver

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service.

Affected products

  • MongoDB C Driver: from 1.10.0, before 1.30.9 (fixed in 1.30.9); from 2.0.0, before 2.5.2 (fixed in 2.5.2)

Published 2026-09-03. Last modified 2026-09-22.