SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84970

MEDIUM · CVSS 6.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A numeric truncation vulnerability in the JSON parsing component of the MongoDB C++ Driver's BSON library allows an attacker to manipulate large input text, potentially leading to memory read beyond the allocated buffer, incomplete document processing, or process termination. This issue affects applications utilizing the library, making it critical for developers and organizations using MongoDB to prioritize remediation to prevent exploitation. No specific MongoDB server configurations or credentials are necessary for the attack, emphasizing the need for vigilance in application security practices.

CVE
CVE-2026-84970
Severity
MEDIUM
CVSS
6.2
EPSS
0.09%
MongoDB

Original NVD Description

A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer and return it to the caller, to silently accept only part of the input as a complete document, or to terminate the process. No MongoDB server, credentials, or non-default configuration is required; the effect is confined to the process that uses the library.

Related CVEs

Other vulnerabilities affecting the same vendor(s)