PatchSiren cyber security CVE debrief
CVE-2026-107325 MongoDB CVE debrief
CVE-2026-107325 debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T19:01:01.894Z and has not been modified since then. The vulnerability is a high-severity issue in the MongoDB Go Driver, which can cause a denial-of-service attack. Defenders and developers using the MongoDB Go Driver, particularly those with versions 1.1.0 to 1.17.10 and 2.0.0 to 2.9.2, should assess their exposure and prioritize patching to prevent potential denial-of-service attacks. The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions.
- Vendor
- MongoDB
- Product
- Go Driver
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and developers using the MongoDB Go Driver, particularly those with versions 1.1.0 to 1.17.10 and 2.0.0 to 2.9.2, should assess their exposure and prioritize patching to prevent potential denial-of-service attacks.
Why it matters
CVE-2026-107325 is a high-severity vulnerability in the MongoDB Go Driver that can cause a denial-of-service attack. Defenders should prioritize patching affected versions and implement compensating controls to detect potential attacks.
- Potential denial-of-service attacks against unprotected applications
- Need to verify and apply patches for affected versions
- Importance of monitoring and exception tracking to detect potential attacks
- Limited information on potential exploits or attacks, requiring caution and verification
Technical summary
The MongoDB Go Driver is vulnerable to a denial-of-service attack due to improper validation of a BSON array length. An unauthenticated actor can supply raw BSON array data to an affected application, causing a runtime panic and terminating the application process. The vulnerability affects versions 1.1.0 to 1.17.10 and 2.0.0 to 2.9.2 of the MongoDB Go Driver. Defenders should prioritize verifying and applying patches for the MongoDB Go Driver to prevent potential denial-of-service attacks. The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions.
Defensive priority
Defenders should prioritize verifying and applying patches for the MongoDB Go Driver, particularly for versions 1.1.0 to 1.17.10 and 2.0.0 to 2.9.2, to prevent potential denial-of-service attacks.
Recommended defensive actions
- Verify and apply patches for the MongoDB Go Driver, particularly for versions 1.1.0 to 1.17.10 and 2.0.0 to 2.9.2
- Review and update inventory to identify and prioritize affected systems
- Implement compensating controls, such as monitoring and exception tracking, to detect potential attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. However, there is limited information on potential exploits or attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107325 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107325
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107325 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107325
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Application denial of service via missing BSON array length validation in MongoDB Go Driver
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107325.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://jira.mongodb.org/browse/GODRIVER-4136
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.