Body:
Detailed steps to reproduce the problem?
Include full traceback, if possible
A document declares size 8. A Boolean field needs 4 bytes of element data (type, key, key terminator, value), but only 3 bytes are available before the document terminator. The value byte at position 7 is the same byte as the document terminator, and the C extension decodes the document instead of rejecting it.
>>> import bson >>> data = b'\x08\x00\x00\x00\x08a\x00\x00' >>> bson.decode(data) {'a': False} >>> bson.is_valid(data) True
The same overlap triggers with Regex (type 0x0b), where the flags string terminator doubles as the document terminator:
>>> bson.decode(b'\x08\x00\x00\x00\x0ba\x00\x00') {'a': Regex('', 0)}
The pure-Python decoder rejects both inputs with InvalidBSON: bad object or element length.
The Boolean handler in bson/_cbsonmodule.c reads its value byte without checking max. The Regex handler checks max < pattern_length + flags_length, which permits the flags terminator to consume the last byte of the document. The bug has been present since PyMongo 1.9.0.
Definition of done: what must be done to consider the task complete?
- The C extension raises InvalidBSON for documents where the last element's value would consume the document terminator byte, matching the pure-Python decoder.
- bson.is_valid() returns False for such documents.
- Add regression tests to cover the cases in the code samples above.
The exact Python version used, with patch level:
Version-independent. Observed on CPython 3.13.13; the defect is in the C extension's bounds checking, not tied to a Python version.
The exact version of PyMongo used, with patch level:
All releases since PyMongo 1.9.0. Observed against 4.18.0.dev0 at commit d03d621e. Requires the C extension (pymongo.has_c() is True); the pure-Python fallback is not affected.
Describe how MongoDB is set up. Local vs Hosted, version, topology, load balanced, etc.
Not applicable. The defect is in client-side BSON parsing and triggers before anything is sent to a server.
The operating system and version (e.g. Windows 7, OSX 10.8, ...)
Not applicable. Every platform using the C extension is affected.
Web framework or asynchronous network library used, if any, with version (e.g. Django 1.7, mod_wsgi 4.3.0, gevent 1.0.1, Tornado 4.0.2, ...)
Not applicable.
Security Vulnerabilities
If you’ve identified a security vulnerability in a driver or any other MongoDB project, please report it according to the instructions here
Assessed as a correctness bug, not a security vulnerability. The misread stays within the document allocation and the decoded result is a normal dict or Regex object, so there are no memory-safety implications. The primary impact is the behavioral difference between the C and pure-Python decoders.