CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-96749

CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

Alon Barad
Alon Barad
Software Engineer

Oct 6, 2026·6 min read·4 visits

Executive Summary (TL;DR)

Compiler optimization of undefined signed integer overflow checks in PyMongo's native BSON encoder leads to heap-based buffer overflow when serializing objects larger than 2GiB.

An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.

Vulnerability Overview

PyMongo, the official client driver for MongoDB, utilizes a performance-optimized C extension to serialize Python dictionary objects into Binary JSON (BSON) byte streams. The primary logic for tracking and reallocating memory during serialization is handled inside the source file bson/buffer.c.

The native encoder maintains an allocated heap buffer, a pointer tracking the stream's position, and an allocation size parameter. The attack surface is exposed when applications serialize untrusted client-provided documents using PyMongo's encoder. If an attacker can inject excessively large elements into the serialization stream, they can trigger arithmetic operations that overflow the memory allocation limits.

This vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), which directly leads to CWE-122 (Heap-based Buffer Overflow). In systems compiled with standard optimization flags, safety checks designed to protect buffer boundaries are optimized out of the final compiled binary. This logic failure can cause memory corruption, service crashes, or potential code execution.

Root Cause Analysis

The underlying flaw resides in the validation logic of the buffer_assure_space function in bson/buffer.c. The function checks whether the native buffer contains enough memory to accommodate incoming serialized BSON elements, attempting to grow the heap buffer if the size limit is exceeded.

The tracking variables buffer->position (current write offset), size (bytes to write), and buffer->size (total capacity) are declared as signed 32-bit integers (int). When a single document contains cumulative serialized elements totaling more than 2GiB, the mathematical operation buffer->position + size exceeds INT_MAX (2,147,483,647) and wraps around to a negative integer.

To prevent this, the developers implemented an overflow guard statement: if (new_size < buffer->position). However, under standard C language specifications, signed integer overflow is classified as Undefined Behavior (UB). Modern optimizing compilers (such as GCC and Clang) assume signed integer overflow is impossible, which permits the compiler to optimize out the guard expression entirely during binary generation.

Furthermore, the logic lacks validation for negative values of the size input parameter. If the compiler strips the overflow guard, the function assumes sufficient space is available and returns success without calling buffer_grow. The serializer then copies raw bytes directly into the under-sized heap buffer, causing a heap-based out-of-bounds write.

Code Analysis

Analyzing the vulnerable implementation reveals how compiler optimization undermines safety assumptions when compiling signed integer calculations.

/* Vulnerable code in PyMongo versions prior to 4.18.2 */
static int buffer_assure_space(buffer_t buffer, int size) {
    int new_size = buffer->position + size;
    
    /* Check for overflow. 
     * Highly optimizing compilers strip this conditional block because
     * signed overflow is Undefined Behavior and assumed mathematically impossible. */
    if (new_size < buffer->position) {
        PyErr_SetString(PyExc_ValueError,
                        "Document would overflow BSON size limit");
        return 1;
    }
 
    if (new_size <= buffer->size) {
        return 0;
    }
    return buffer_grow(buffer, new_size);
}

The patched version resolves this vulnerability by ensuring arithmetic operations are calculated in a wider, non-overflowing integer type.

/* Patched code in PyMongo version 4.18.2 */
static int buffer_assure_space(buffer_t buffer, int size) {
    long long new_size;
    
    /* Explicitly check and reject negative sizes */
    if (size < 0) {
        PyErr_SetString(PyExc_ValueError,
                        "Document would overflow BSON size limit");
        return 1;
    }
 
    /* Perform calculation in a 64-bit container to prevent signed overflow */
    new_size = (long long)buffer->position + (long long)size;
    
    /* Validate the 64-bit result directly against 32-bit INT_MAX limits */
    if (new_size > INT_MAX) {
        PyErr_SetString(PyExc_ValueError,
                        "Document would overflow BSON size limit");
        return 1;
    }
 
    if ((int)new_size <= buffer->size) {
        return 0;
    }
    return buffer_grow(buffer, (int)new_size);
}

Upcasting the operands to long long guarantees the addition will not overflow the machine register. The explicit check against INT_MAX ensures that the subsequent downcast back to a 32-bit int is mathematically safe. This approach prevents compilers from optimizing away the boundary verification checks.

Exploitation Methodology

To exploit this vulnerability, an attacker must trigger an execution path where the PyMongo client driver serializes an exceptionally large document exceeding 2GiB in size. This requirement makes the vulnerability most exploitable on 64-bit operating systems where the Python interpreter can allocate massive objects in system memory.

The attacker crafts and transmits structured input (such as nested dictionary structures or long string values) to an endpoint that passes the payload directly to PyMongo serialization functions (e.g., bson.encode or database insert commands). The PyMongo C extension loops over the elements, sequentially calling buffer_assure_space.

As the size parameter overflows the signed 32-bit boundary, the compiler-optimized binary skips the heap-allocation check and returns success. When the native driver attempts to copy data, the memory operations write past the limits of the allocated buffer, corrupting adjacent heap structures, allocator metadata, or Python heap pointers. This sequence of events is illustrated below:

Impact Assessment

A successful heap out-of-bounds write can result in immediate system instability or arbitrary code execution. The primary impact is denial of service (DoS) due to memory violations. When the application writes outside the heap bounds, it corrupts critical heap metadata, resulting in an unrecoverable segmentation fault.

Under specific memory layout conditions, an attacker can overwrite adjacent heap structures, such as Python object pointers or standard allocator headers. By carefully structuring the payload to place shellcode addresses in overwritten function pointers, an attacker can potentially hijack application execution flow.

While CVSS assigns a Local (L) attack vector, any remote-facing application that accepts and serializes user-supplied document structures without size restrictions elevates this vulnerability to an unauthenticated remote execution vector. The threat level is significant for large-scale data processing systems and database pipelines.

Remediation & Defensive Strategies

The definitive remediation is upgrading PyMongo to version 4.18.2 or higher. The updated package implements proper integer upcasting and explicitly checks limits against INT_MAX inside bson/buffer.c.

If upgrading is not immediately possible, organizations can apply a software workaround by disabling PyMongo's native C extensions. Setting the environment variable PYTHON_BSON_EXTENSIONS=0 forces PyMongo to use its pure-Python implementation of BSON serialization, which is immune to buffer overflows due to Python's arbitrary-precision integers.

Additionally, applications should implement strict input size validation. Because MongoDB natively enforces a 16MB document size limit, applications should reject any payloads approaching this limit at the API gateway layer before they reach the database driver. This configuration reduces risk and protects against resource depletion.

Official Patches

MongoDBHarden BSON buffer size guard against signed integer overflow

Fix Analysis (1)

Technical Appendix

CVSS Score
8.4/ 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Probability
0.13%
Top 98% most exploited

Affected Systems

Applications running on 64-bit architectures using PyMongo with native C extensions enabled.

Affected Versions Detail

Product
Affected Versions
Fixed Version
PyMongo
MongoDB
>= 1.9.0, < 4.18.24.18.2
AttributeDetail
CWE IDCWE-190 (Integer Overflow or Wraparound), CWE-122 (Heap-based Buffer Overflow)
Attack VectorLocal (Elevated to Remote if exposing serialization endpoints)
CVSS v3.1 Score8.4 (High Severity)
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score0.00132 (0.13% probability of exploitation)
Exploit StatusNone (No public exploits or wild-exploitation documented)
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1203Exploitation for Client Execution
Execution
CWE-190
Integer Overflow or Wraparound

An integer overflow occurs when an arithmetic operation attempts to create a numeric value that is outside of the range that can be represented with a given number of bits.

Vulnerability Timeline

Vulnerability identified and preliminary developer builds initialized.
2026-09-10
Vulnerability patched and released in PyMongo version 4.18.2; official CVE-2026-96749 assigned.
2026-09-24
Global OSV and vulnerability databases updated.
2026-10-01

References & Sources

  • [1]GitHub Security Advisory GHSA-v4x9-3549-crwv
  • [2]NVD CVE-2026-96749 Analysis
  • [3]PyMongo Bug Merge Commit
  • [4]PyMongo Fix Commit
  • [5]PyMongo Pull Request 3066
  • [6]PyMongo Release 4.18.2
  • [7]PyMongo 4.18.2 Changelog
  • [8]CVE-2026-96749 Record
  • [9]Wiz Vulnerability Analysis Data

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•10 minutes ago•CVE-2026-96748
8.3

CVE-2026-96748: Host Injection Vulnerability in PyMongo Connection String Parsing

A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.

Amit Schendel
Amit Schendel
1 views•7 min read
•about 2 hours ago•CVE-2026-102827
8.1

CVE-2026-102827: Command and Argument Injection Bypass in simple-git via Option Abbreviation

CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.

Alon Barad
Alon Barad
6 views•7 min read
•about 3 hours ago•CVE-2026-102826
8.1

CVE-2026-102826: Argument Validation Bypass and Command Injection in simple-git

CVE-2026-102826 is a critical security vulnerability discovered in the simple-git library for Node.js, affecting all versions prior to v4.0.0. The vulnerability allows remote attackers to bypass the library's built-in argument validation rules using conditional configuration includes and abbreviated Command Line Interface (CLI) options. By injecting custom arguments into Git execution pipelines, an attacker can force the application to load a malicious local configuration file, resulting in arbitrary OS command execution under the privileges of the parent Node.js process.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-102828
9.2

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

Amit Schendel
Amit Schendel
9 views•5 min read
•about 5 hours ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
6 views•5 min read
•about 6 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
9 views•7 min read