Bug 2525215 (CVE-2026-81521) - CVE-2026-81521 go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite
Summary: CVE-2026-81521 go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirect...
Keywords:
Status: NEW
Alias: CVE-2026-81521
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-27 20:17 UTC by OSIDB Bzimport
Modified: 2026-09-16 17:22 UTC (History)
136 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:68334 0 None None None 2026-09-16 17:22:41 UTC

Description OSIDB Bzimport 2026-08-27 20:17:14 UTC
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.

Comment 1 Jon Orris 2026-09-16 17:22:35 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334


Note You need to log in before you can comment on or make changes to this bug.