BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities.
Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755.
BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.
Metrics
Affected Vendors & Products
References
History
Sat, 17 May 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 16 May 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported. | |
Title | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities | |
Weaknesses | CWE-1104 CWE-1395 |
|
References |
|

Status: PUBLISHED
Assigner: CPANSec
Published: 2025-05-16T15:15:49.810Z
Updated: 2025-05-17T02:39:15.690Z
Reserved: 2025-04-16T09:05:34.360Z
Link: CVE-2025-40906

Updated: 2025-05-17T02:39:11.007Z

Status : Received
Published: 2025-05-16T16:15:41.493
Modified: 2025-05-17T03:16:49.357
Link: CVE-2025-40906

No data.