{"id":"BIT-mongodb-2025-0755","summary":"MongoDB C Driver bson library may be susceptible to buffer overflow","details":"The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16","aliases":["CVE-2025-0755"],"modified":"2025-11-06T13:25:46.476Z","published":"2025-09-23T08:46:21.341Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*"]},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/CDRIVER-5601"},{"type":"WEB","url":"https://jira.mongodb.org/browse/SERVER-94461"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0755"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html"}],"affected":[{"package":{"name":"mongodb","ecosystem":"Bitnami","purl":"pkg:bitnami/mongodb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.0.16"},{"introduced":"8.0.0"},{"fixed":"8.0.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2025-0755.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}],"schema_version":"1.7.3"}