{"id":"CVE-2021-20329","aliases":["GHSA-f6mq-5m25-4r72","GO-2021-0112"],"url":"https://o3.security/vulnerability/CVE-2021-20329","summary":"go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON","details":"Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.","published":"2021-06-10T17:15:08.047Z","modified":"2026-07-08T11:47:35.270366Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"go.mongodb.org/mongo-driver","fixedVersion":"1.5.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/mongodb/mongo-go-driver/releases/tag/v1.5.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:47:35.270366Z"}}