highCVSS 8.4Vulnerability
CVE-2026-96749
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
Properties
- severity
- high
- summary
- PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
- epss_score
- 0.00132
- cvss_score
- 8.4
- retrieved_at
- 2026-10-06T03:06:48+00:00
- ghsa_published
- 2026-10-05T23:47:10Z
- source_url
- https://github.com/advisories/GHSA-v4x9-3549-crwv
- ghsa_updated
- 2026-10-05T23:47:11Z
- ghsa_id
- GHSA-v4x9-3549-crwv
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-96749
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- signal_observed_at
- 2026-10-06T02:58:31+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.02361
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]pip/pymongo
AFFECTS (1)
→[Software]pip/pymongo
HAS_WEAKNESS (1)
→[Weakness]Integer Overflow or Wraparound
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph