Warning
Go Driver versions v2.1.0 through v2.8.1 and v2.9.0 through v2.9.1 are affected by a security issue CVE-2026-81521 in
Client.BulkWrite. The fix shipped in v2.8.2 but was not included in v2.9.0 or v2.9.1. This release restores the fix for the 2.9 line. Users on v2.9.0 or v2.9.1 are encouraged to upgrade to Go Driver v2.9.2 as soon as possible.
The MongoDB Go Driver Team is pleased to release version 2.9.2 of the MongoDB Go Driver.
This release addresses CVE-2026-81521, a security issue in calling Client.BulkWrite. A caller-controlled database name containing a period (.) may be interpreted as a different namespace when forwarded to MongoDB. This could redirect operations to a database or collection other than the one intended by the application. It also restores a fix from v2.8.1 for operations such as Database.RunCommand returning a nil error when a command failed with NoWritesPerformed. For more information please see the 2.9.2 release notes.
You can obtain the driver source from GitHub under the v2.9.2 tag.
Documentation for the Go Driver can be found on pkg.go.dev and the MongoDB documentation site.
BSON library documentation is also available on pkg.go.dev.
For issues with, questions about, or feedback for the Goour supportchannels, including StackOverflow.
Bugs can be reported in the Go Driver project in the MongoDB JIRA where a list of current issues can be found.
Your feedback on the Go Driver is greatly appreciated!
Thank you,
The Go Driver Team
It follows the 2.9.1 post’s structure. I also joined thethe original (the documentation and JIRA sentences). Therelease-notes link will only work once the v2.9.2 GitHubpost this after that.