VendorsMongoDBjs-bsonall versions
Vulnerabilities

MongoDB JS-BSON

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-13863
The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long untrusted string.
Published 2018-07-10 · Modified
7.5EPSS 0.019
CVE-2019-2391
JS-bson may incorrectly serialise some requests
Published 2020-03-31 · Modified
5.5EPSS 0.009