PatchSiren cyber security CVE debrief
CVE-2026-106437 MongoDB CVE debrief
CVE-2026-106437 is an out-of-bounds read and write vulnerability via undersized BSON buffer reservation in the MongoDB C Driver. An application using the driver can be made to terminate or read or corrupt adjacent process memory if an actor can influence the length supplied by an embedding application. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity. It requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation. Defenders should assess exposure and prioritize verification and remediation efforts.
- Vendor
- MongoDB
- Product
- C Driver
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for maintaining and securing applications that use the MongoDB C Driver should assess exposure and prioritize verification and remediation efforts. This includes reviewing application code, verifying input validation and sanitization, and updating to a fixed version of the driver if necessary. Additionally, defenders should consider implementing compensating controls and monitoring for exposed assets.
Why it matters
CVE-2026-106437 is a medium-severity vulnerability in the MongoDB C Driver that can lead to application termination or memory corruption if exploited. Defenders should prioritize verifying and updating to a fixed version, especially for applications handling user-supplied input.
- Potential application termination or crash.
- Possible read or corruption of adjacent process memory.
- Requires verification of input validation and sanitization in affected applications.
- Remediation priority for updating to a fixed version of the MongoDB C Driver.
Technical summary
The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. This occurs because the API does not enforce the minimum BSON size requirement. An attacker who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. The affected versions of the MongoDB C Driver are 1.4.0 to 1.30.13 and 2.0.0 to 2.5.6.
Defensive priority
Defenders should prioritize verifying and updating to a fixed version of the MongoDB C Driver, especially for applications that handle user-supplied or untrusted input.
Recommended defensive actions
- Verify the version of the MongoDB C Driver in use and update to a fixed version if necessary.
- Review application code to ensure that input is validated and sanitized.
- Consider implementing additional security measures to prevent exploitation.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its CVSS score of 5.9 and MEDIUM severity. The affected versions of the MongoDB C Driver are 1.4.0 to 1.30.13 and 2.0.0 to 2.5.6.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106437 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106437
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106437 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106437
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106437.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://jira.mongodb.org/browse/CDRIVER-6423
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.