CVE-2026-96749: Heap Out-of-Bounds Write in PyMongo BSON Encoder
PyMongo has a high-severity flaw, CVE-2026-96749 (CVSS 8.4), where compiler optimization removes signed integer overflow checks in the native BSON encoder, enabling a heap-based out-of-bounds write when serializing documents larger than 2GiB. Versions 1.9.0 through 4.18.1 are affected; the fix ships in 4.18.2.
- CVSS 8.4, CWE-190 and CWE-122, no public exploits documented
- Affects PyMongo >= 1.9.0 and < 4.18.2, fixed in 4.18.2
- Triggered by serializing documents larger than 2GiB
- Workaround: set PYTHON_BSON_EXTENSIONS=0 or cap input size
Read next
Security