AZL-105110

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105110.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-105110
Upstream
Published
2026-09-24T19:17:20Z
Modified
2026-10-02T05:31:52Z
Summary
CVE-2026-96749 affecting package python-pymongo 4.2.0-9
Details

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.

References

Affected packages

Azure Linux:3 / python-pymongo

Package

Name
python-pymongo
Purl
pkg:rpm/azure-linux/python-pymongo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.2.0-9

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105110.json"