{"id":"CVE-2026-96749","published":"2026-09-24T19:17:20.963","lastModified":"2026-09-26T04:17:52.260","description":"An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.","cvssScore":8.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-190"],"vendors":[],"products":[],"references":[{"url":"https://github.com/mongodb/mongo-python-driver/blob/4.18.2/doc/changelog.rst","tags":[]},{"url":"https://github.com/mongodb/mongo-python-driver/releases/tag/4.18.2","tags":[]},{"url":"https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv","tags":[]}],"exploitRefs":[{"url":"https://github.com/mongodb/mongo-python-driver/blob/4.18.2/doc/changelog.rst","tags":[]},{"url":"https://github.com/mongodb/mongo-python-driver/releases/tag/4.18.2","tags":[]},{"url":"https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv","tags":[]}],"hasPoc":true,"ai":null}