CVE-2026-84970CWE-681

CVE-2026-84970

Medium · published September 3, 2026

CVSS v3.1
6.2
EPSS
0%
Percentile
0.9
In the wild
Unconfirmed
What it is

A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer and return it to the caller, to silently accept only part of the input as a complete document, or to terminate the process. No MongoDB server, credentials, or non-default configuration is required; the effect is confined to the process that uses the library.

The record
Technical detail
CVSS v3.1
6.2 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS v4.0
5.9 · CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS
0.00099 · 0.9th percentile
Weakness
CWE-681 · Incorrect Conversion between Numeric Types
Published
2026-09-03T19:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 14:56Z
    Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser
    cvelistv5