{"id":"CVE-2025-40906","summary":"BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities","details":"BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities.\n\nThose include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. \n\nBSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.","modified":"2026-08-12T03:51:26.443148821Z","published":"2025-05-16T15:15:49.810Z","database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-1104","CWE-122","CWE-1395","CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40906.json"},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40906.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40906"},{"type":"ADVISORY","url":"https://www.mongodb.com/community/forums/t/mongodb-perl-driver-end-of-life/7890"},{"type":"PACKAGE","url":"https://github.com/mongodb-labs/mongo-perl-bson-xs"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb-labs/mongo-perl-bson-xs","events":[{"introduced":"0"},{"last_affected":"8a7db1d4d97d424197b1b7308c5face433e9af00"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.8.4"}],"source":"AFFECTED_FIELD"}}],"versions":["release-v0.8.4","release-v0.8.3","release-v0.8.2","release-v0.8.1","release-v0.8.0","release-v0.6.0","release-v0.4.6","release-v0.4.5","release-v0.4.4","release-v0.4.3","release-v0.4.2","release-v0.4.1","release-v0.4.0","release-v0.2.2","release-v0.2.1","release-v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40906.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}