
CVE-2026-106431 An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a sp… https://www.cve.org/CVERecord?id=CVE-2026-106431
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-106431 An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a sp… https://www.cve.org/CVERecord?id=CVE-2026-106431