CVE-2021-20329

MEDIUM

MongoDB GO Driver <1.5.0 - Code Injection

Title source: llm

Description

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

Scores

CVSS v3 6.8
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-20 CWE-1287
Status published

Affected Products (2)

mongodb/go_driver < 1.5.0
go.mongodb.org/mongo-driver < 1.5.1Go

Timeline

Published Jun 10, 2021
Tracked Since Feb 18, 2026