Junglewise Threat Intelligence

CVE-2026-84970: MongoDB C++ Driver BSON library numeric truncation in JSON parsing

CVE-2026-84970 · Severity: medium · CVSS 6.2 · Published 2026-09-03

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

The MongoDB C++ Driver's BSON JSON parsing library contains a numeric truncation vulnerability that can be exploited by providing specially crafted JSON input larger than 2 GB. An attacker who can control the JSON text sent to the library can cause it to read beyond allocated memory buffers, potentially exposing sensitive data, silently accepting incomplete input as valid documents, or crashing the application. This affects any application using the driver's JSON parsing interface, regardless of whether it connects to a MongoDB server.

Technical details

The vulnerability is a numeric truncation weakness in the JSON parsing component of MongoDB C++ Driver's BSON library, specifically in the from_json() function. When processing JSON input larger than 2^31 bytes, the input length is cast to a signed int32_t, causing the size to truncate to a negative value. This allows the underlying strlen-based parsing logic to read past the end of the allocated buffer. The vulnerability requires only that an attacker control the JSON text passed to the public JSON parsing interface; no MongoDB server credentials or non-default configuration is needed. An exploit can result in out-of-bounds memory reads, silent acceptance of incomplete input, or process termination. The issue was fixed in version 4.5.2 by adding validation to throw an exception if the input length does not safely cast to int32_t.

Affected products

  • MongoDB C++ Driver before 4.5.2

Timeline

  • 2026-09-03: disclosed: CVE-2026-84970 published
  • 2026-09-04: patched: Fixed in version 4.5.2

References

Related threats