Vulnerability Description
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html
- https://www.mongodb.com/community/forums/t/mongodb-perl-driver-end-of-life/7890
FAQ
What is CVE-2025-40906?
CVE-2025-40906 is a vulnerability with a CVSS score of 9.8 (CRITICAL). BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-...
How severe is CVE-2025-40906?
CVE-2025-40906 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-40906?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.