Executive brief
The MongoDB BI Connector ODBC Driver contains a memory safety vulnerability triggered by SQL statements with exceptionally long digit sequences in the LIMIT clause. When the driver's prefetch feature is enabled, an attacker can craft a malicious SQL query to cause the application to crash or corrupt memory, disrupting service or potentially leading to data compromise. This affects any application using the driver to query MongoDB through ODBC connections.
Technical details
This is a classic buffer overflow vulnerability in the ODBC driver's get_limit method. The vulnerable code copies digit sequences from SQL LIMIT clauses into a fixed-size internal buffer without bounds checking. The vulnerability is triggered only when the driver's prefetch optimization is enabled. An attacker who can influence SQL query construction (via application input, query builder, or direct query submission) can supply an abnormally long numeric LIMIT value to overflow the buffer. Successful exploitation causes denial of service (process crash) or memory corruption that may enable code execution. MongoDB patched this in version 1.4.10 with an added bounds check to the get_limit method.
Affected products
- MongoDB BI Connector ODBC Driver before 1.4.10
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Fixed in version 1.4.10