CVE-2026-84966CWE-681

CVE-2026-84966

Medium · published September 3, 2026

CVSS v3.1
5.1
EPSS
0%
Percentile
1.3
In the wild
Unconfirmed
What it is

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate the calling process. No authentication is required, but the calling application must pass the oversized name in a specific form.

The record
Technical detail
CVSS v3.1
5.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
5.9 · CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00109 · 1.3th percentile
Weakness
CWE-681 · Incorrect Conversion between Numeric Types
Published
2026-09-03T20:18Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 15:00Z
    BSON element injection via NUL-embedded document keys in builder append
    cvelistv5