PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106437 MongoDB CVE debrief

CVE-2026-106437 is an out-of-bounds read and write vulnerability via undersized BSON buffer reservation in the MongoDB C Driver. An application using the driver can be made to terminate or read or corrupt adjacent process memory if an actor can influence the length supplied by an embedding application. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity. It requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation. Defenders should assess exposure and prioritize verification and remediation efforts.

Vendor
MongoDB
Product
C Driver
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for maintaining and securing applications that use the MongoDB C Driver should assess exposure and prioritize verification and remediation efforts. This includes reviewing application code, verifying input validation and sanitization, and updating to a fixed version of the driver if necessary. Additionally, defenders should consider implementing compensating controls and monitoring for exposed assets.

Why it matters

CVE-2026-106437 is a medium-severity vulnerability in the MongoDB C Driver that can lead to application termination or memory corruption if exploited. Defenders should prioritize verifying and updating to a fixed version, especially for applications handling user-supplied input.

  • Potential application termination or crash.
  • Possible read or corruption of adjacent process memory.
  • Requires verification of input validation and sanitization in affected applications.
  • Remediation priority for updating to a fixed version of the MongoDB C Driver.

Technical summary

The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. This occurs because the API does not enforce the minimum BSON size requirement. An attacker who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. The affected versions of the MongoDB C Driver are 1.4.0 to 1.30.13 and 2.0.0 to 2.5.6.

Defensive priority

Defenders should prioritize verifying and updating to a fixed version of the MongoDB C Driver, especially for applications that handle user-supplied or untrusted input.

Recommended defensive actions

  • Verify the version of the MongoDB C Driver in use and update to a fixed version if necessary.
  • Review application code to ensure that input is validated and sanitized.
  • Consider implementing additional security measures to prevent exploitation.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its CVSS score of 5.9 and MEDIUM severity. The affected versions of the MongoDB C Driver are 1.4.0 to 1.30.13 and 2.0.0 to 2.5.6.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106437 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106437

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106437 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106437

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.