Full Report
MongoDB security advisory (AV26-1024)
Analysis Summary
# Vulnerability: Multiple Flaws in MongoDB Go Driver and libmongocrypt
## CVE Details
*Note: The provided source lists specific Jira trackers but does not explicitly list CVE identifiers. Based on the technical descriptions:*
- **CVE ID:** Pending/Not explicitly listed in source
- **CVSS Score:** Not provided (Likely Medium to High based on BSON overflow/parsing issues)
- **CWE:** CWE-190 (Integer Overflow), CWE-20 (Improper Input Validation), CWE-670 (Always-Incorrect Control Flow)
## Affected Systems
- **Products:** MongoDB Go Driver, libmongocrypt
- **Versions:**
- Go Driver: Versions prior to 2.9.0 and 2.9.2
- libmongocrypt: Versions prior to 1.20.5
- **Configurations:** Systems utilizing Client-Side Field Level Encryption (CSFLE) or Queryable Encryption (via libmongocrypt) and applications processing untrusted BSON data (via Go Driver).
## Vulnerability Description
This advisory covers three distinct technical flaws:
1. **BSON Length Validation (GODRIVER-4136):** The Go Driver failed to validate if BSON lengths were below the mandatory 5-byte minimum before performing slicing operations. This can lead to out-of-bounds memory access or panics.
2. **Integer Overflow (GODRIVER-4102):** A flaw in `bsoncore.valueLength` where the driver failed to reject `int32` length overflows. An attacker could potentially craft malicious BSON documents to trigger unexpected behavior or crashes.
3. **KEK Parsing Issue (MONGOCRYPT-964):** In `libmongocrypt`, duplicate `masterKey` fields would re-parse into the same Key Encryption Key (KEK). This relates to how encrypted fields are handled and could lead to inconsistencies in cryptographic operations.
## Exploitation
- **Status:** Not exploited in the wild (based on current reporting)
- **Complexity:** Medium
- **Attack Vector:** Network (Remote) - Typically triggered by sending malformed BSON payloads to an application using the vulnerable driver/library.
## Impact
- **Confidentiality:** Low (Potential info leak via malformed BSON)
- **Integrity:** Medium (Potential for cryptographic inconsistency in libmongocrypt)
- **Availability:** High (Risk of application crashes/DoS due to overflow and slicing errors)
## Remediation
### Patches
Users should upgrade to the following versions immediately:
- **MongoDB Go Driver:** Update to version **2.9.2** or later.
- **libmongocrypt:** Update to version **1.20.5** or later.
### Workarounds
- Validate all incoming BSON data at the application layer before passing it to the driver, if possible.
- Limit network exposure to trusted clients only to reduce the risk of malformed payload injection.
## Detection
- **Indicators of Compromise:** Look for application crashes (panics) associated with BSON decoding or slicing in Go application logs.
- **Detection methods:** Use software composition analysis (SCA) tools to identify vulnerable versions of `go.mongodb.org/mongo-driver` and `libmongocrypt`.
## References
- [hXXps://jira.mongodb.org/browse/MONGOCRYPT-964]
- [hXXps://jira.mongodb.org/browse/GODRIVER-4102]
- [hXXps://jira.mongodb.org/browse/GODRIVER-4136]
- [hXXps://www.cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory-av26-1024]