{"id":"AZL-105110","summary":"CVE-2026-96749 affecting package python-pymongo 4.2.0-9","details":"An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.","modified":"2026-10-02T05:31:52Z","published":"2026-09-24T19:17:20Z","upstream":["CVE-2026-96749"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96749"}],"affected":[{"package":{"name":"python-pymongo","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-pymongo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.2.0-9"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105110.json"}}],"schema_version":"1.9.0"}