CVE-2023-0437
MEDIUMMongoDB C Driver < 1.25.0 - Denial of Service via Infinite Loop in bson_utf8_validate
Title source: llmDescription
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.
References (4)
Core 4
Core References
Issue Tracking, Vendor Advisory
https://jira.mongodb.org/browse/CDRIVER-4747
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/7GUVOAFZFSYTNBF6R7H4XJM5DHWBRQ6P/
Scores
CVSS v3
5.3
EPSS
0.0110
EPSS Percentile
61.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (1)
mongodb/c_driver
< 1.25.0
Published
Jan 12, 2024
Tracked Since
Feb 18, 2026