Bug 2525215 (CVE-2026-81521)

Summary: CVE-2026-81521 go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, agarcial, akhatavk, akostadi, akoudelk, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, aoconnor, aos-team-art-private, asdas, asegurap, bniver, bparees, cahl, cmah, derez, dfreiber, dhanak, dkeler, dmayorov, dpaolell, drosa, drow, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, ebourniv, eglynn, flucifre, gbenhaim, gmeno, gparvin, groman, hasun, ibolton, jbritton, jburrell, jcantril, jchui, jdelft, jfula, jhe, jjoyce, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jprabhak, jpretori, jsamir, jschluet, jtolenti, jupierce, kaycoth, kbempah, kingland, kshier, ktsao, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, ljawale, mbenjamin, mbiarnes, mburns, mgarciac, mhackett, mnovotny, msilmser, mwringe, nboldt, ngough, niyer, nyancey, oaljalju, ometelka, pakotvan, pantinor, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, rekumar, rhaigner, rhel-process-autobot, rjohnson, rojacob, sakbas, sausingh, sbratsla, sbunciak, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, solenoci, sostapov, sseago, stcannon, sthirugn, suppawar, syedriko, teagle, thason, tsedmik, twaugh, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the MongoDB Go Driver. The `Client.BulkWrite` operation does not properly validate database names, allowing a specially crafted name with reserved characters to redirect write operations. This vulnerability could enable an attacker to modify or corrupt data in unintended databases and collections.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-27 20:17:14 UTC
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.

Comment 1 Jon Orris 2026-09-16 17:22:35 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334