Clustered Index names allow null embedded bytes

XMLWordPrintableJSON

    • Type: Bug
    • Resolution: Fixed
    • Priority: Major - P3
    • 9.1.0-rc0, 8.3.9, 9.0.0-rc2
    • Affects Version/s: 9.0 Required
    • Component/s: None
    • None
    • Storage Execution
    • Fully Compatible
    • ALL
    • v9.0, v8.3, v8.2, v8.0, v7.0
    • Storage Execution 2026-08-03
    • 200
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Discovered via the fuzzer. Attaching a minimal reproducer. I would recommend updating the up-front validation of clustered index names.

      One of the problems with storing embedded null bytes in an index name is that collStats cannot represent the name in BSON since SERVER-95279 introduced stronger checks in the server.

        1. server_132463_repro.js
          1 kB
          Matt Kneiser

            Assignee:
            Matt Kneiser
            Reporter:
            Matt Kneiser
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: