Executive brief
The MongoDB BI Connector ODBC Driver, used to query MongoDB databases from BI tools and applications, does not properly validate the size of floating-point numbers when converting them to text. An attacker who can insert data into a collection could store a specially crafted large floating-point value that, when read through the connector, causes the driver to write beyond allocated memory and crash the reading application.
Technical details
The vulnerability is a classic buffer overflow in the ODBC driver's floating-point to text conversion logic. The driver converts floating point values without bounds-checking, allowing large values to overflow the destination buffer and corrupt adjacent memory. The attack requires the ability to store malicious data in a MongoDB collection that is then queried through the BI Connector; network-based remote exploitation is not direct, but depends on application context. An attacker with write access to MongoDB can reliably crash consuming applications, leading to denial of service. A patch was released in version 1.4.9 that clamps large floats during string conversion.
Affected products
- MongoDB BI Connector ODBC Driver before 1.4.9
Timeline
- 2026-08-12: disclosed
- 2026-08-06: patched: Version 1.4.9 released