Security Advisory

CVE-2025-0755

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-18 09:01:04
Last updated 2025-11-03 19:35:09
Assigner mongodb
State PUBLISHED

Description

The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16