DEBIAN-CVE-2026-84970

Source
https://security-tracker.debian.org/tracker/CVE-2026-84970
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84970.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-84970
Upstream
Published
2026-09-03T15:17:36Z
Modified
2026-09-11T09:02:56Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer and return it to the caller, to silently accept only part of the input as a complete document, or to terminate the process. No MongoDB server, credentials, or non-default configuration is required; the effect is confined to the process that uses the library.

References

Affected packages

Debian:14 / mongo-cxx-driver

Package

Name
mongo-cxx-driver
Purl
pkg:deb/debian/mongo-cxx-driver?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.5.2-1

Affected versions

3.*
3.4.1-1
3.6.0-1
3.6.1-1
3.6.2-1
3.6.3-1
3.6.5-1
3.6.6-1
3.6.7-1
3.7.0-1
3.7.1-1
3.8.0-1
3.8.1-1
3.9.0-1
3.10.1-1
3.10.2-1
3.11.0-1
4.*
4.0.0-1
4.1.4-1
4.4.0-1
4.5.0-1
4.5.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84970.json"