Skip to content

chore(deps): bump go.mongodb.org/mongo-driver/v2 from 2.9.0 to 2.9.1 in /agent - #13768

Closed
dependabot[bot] wants to merge 1 commit into
dev-v2from
dependabot/go_modules/agent/go.mongodb.org/mongo-driver/v2-2.9.0
Closed

dependabot[bot] wants to merge 1 commit into
dev-v2from
dependabot/go_modules/agent/go.mongodb.org/mongo-driver/v2-2.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps go.mongodb.org/mongo-driver/v2 from 2.9.0 to 2.9.1.

Release notes

Sourced from go.mongodb.org/mongo-driver/v2's releases.

MongoDB Go Driver 2.9.1

The MongoDB Go Driver Team is pleased to release version 2.9.1 of the official MongoDB Go Driver.

Release Highlights

[!WARNING]
Go Driver versions v1.0.0 through v1.17.9 and v2.0.0 through v2.9.0 are affected by a security issue CVE-2026-88031 in the GridFS delete methods. This release resolves that security issue in Go Driver v2. Users are encouraged to upgrade to Go Driver v2.9.1 as soon as possible. For the fix in Go Driver v1, see the v1.17.10 release.

This release addresses CVE-2026-88031, a security issue in GridFS delete methods where the file ID lookup could match more loosely than intended, potentially causing unintended file (and chunk) deletions instead of an exact match on the given file ID.

Users can manually restrict the file ID with a $eq operator before passing it to GridFSBucket methods using code like the following.

func exactMatch(id any) bson.D {
	return bson.D{{"$eq", id}}
}
// e.g., for v2, (*GridFSBucket).Delete() with an exact match on the file ID.
gridFSBucket.Delete(context.TODO(), exactMatch(id))

What's Changed

馃悰 Fixed

  • GODRIVER-4081: Use exact match for file ID in GridFS delete methods. by @鈥媞ingyang-hu

Full Changelog: v2.9.0...v2.9.1

For a full list of tickets included in this release, please see the list of fixed issues.

Documentation for the Go Driver can be found on pkg.go.dev and the MongoDB documentation site. BSON library documentation is also available on pkg.go.dev. For issues with, questions about, or feedback for the Go Driver, please look into our support channels, including StackOverflow. Bugs can be reported in the Go Driver project in the MongoDB JIRA where a list of current issues can be found. Your feedback on the Go Driver is greatly appreciated!

Commits
  • 5d8c3a2 BUMP v2.9.1
  • ba2ddbf Merge commit from fork
  • 9a88e59 Merge branch 'release/2.9' into godriver4081-gridFsId
  • 0241bcf update prose test
  • 81d1fde GODRIVER-4081 Use exact match for file ID in GridFS delete methods.
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 9, 2026
Bumps [go.mongodb.org/mongo-driver/v2](https://github.com/mongodb/mongo-go-driver) from 2.9.0 to 2.9.1.
- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)
- [Commits](mongodb/mongo-go-driver@v2.9.0...v2.9.1)

---
updated-dependencies:
- dependency-name: go.mongodb.org/mongo-driver/v2
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump go.mongodb.org/mongo-driver/v2 from 2.8.2 to 2.9.0 in /agent chore(deps): bump go.mongodb.org/mongo-driver/v2 from 2.9.0 to 2.9.1 in /agent Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/agent/go.mongodb.org/mongo-driver/v2-2.9.0 branch from 015142b to bea4856 Compare September 29, 2026 13:39
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #13961.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/agent/go.mongodb.org/mongo-driver/v2-2.9.0 branch September 30, 2026 08:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants