chiprook
← Security
SecurityOctober 6, 2026, 15:31

CVE-2026-96749: Heap Out-of-Bounds Write in PyMongo BSON Encoder

PyMongo has a high-severity flaw, CVE-2026-96749 (CVSS 8.4), where compiler optimization removes signed integer overflow checks in the native BSON encoder, enabling a heap-based out-of-bounds write when serializing documents larger than 2GiB. Versions 1.9.0 through 4.18.1 are affected; the fix ships in 4.18.2.

CVE-2026-96749: Heap Out-of-Bounds Write in PyMongo BSON Encoder
#MongoDB#PyMongo
Read next
Security

CVE-2026-86510: out-of-bounds write in D-Link DIR-822A L2TP daemon

AI

Knowledgator Releases GLiFormer: A 575M-Parameter Encoder That Hits 91.10 F1 on Nested JSON Extraction Without Generating Tokens

Security

Codex sandbox escape: token in shared heap and apply_patch grant on /tmp

Security

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed