{"record":{"id":"2bfd018e0aba3f98","repo":"mongodb/node-mongodb-native","slug":"negative-binary-type-element-size-found-for-subtyp","errorCode":null,"errorMessage":"Negative binary type element size found for subtype 0x02","messagePattern":"Negative binary type element size found for subtype 0x02","errorType":"exception","errorClass":"BSONError","httpStatus":null,"severity":"error","filePath":"src/cmap/wire_protocol/on_demand/document.ts","lineNumber":204,"sourceCode":"        return NumberUtils.getInt32LE(this.bson, offset);\n      case BSONType.long:\n        return NumberUtils.getBigInt64LE(this.bson, offset);\n      case BSONType.bool:\n        return Boolean(this.bson[offset]);\n      case BSONType.objectId:\n        return new ObjectId(this.bson.subarray(offset, offset + 12));\n      case BSONType.timestamp:\n        return new Timestamp(NumberUtils.getBigInt64LE(this.bson, offset));\n      case BSONType.string:\n        return ByteUtils.toUTF8(this.bson, offset + 4, offset + length - 1, false);\n      case BSONType.binData: {\n        const totalBinarySize = NumberUtils.getInt32LE(this.bson, offset);\n        const subType = this.bson[offset + 4];\n\n        if (subType === 2) {\n          const subType2BinarySize = NumberUtils.getInt32LE(this.bson, offset + 1 + 4);\n          if (subType2BinarySize < 0)\n            throw new BSONError('Negative binary type element size found for subtype 0x02');\n          if (subType2BinarySize > totalBinarySize - 4)\n            throw new BSONError('Binary type with subtype 0x02 contains too long binary size');\n          if (subType2BinarySize < totalBinarySize - 4)\n            throw new BSONError('Binary type with subtype 0x02 contains too short binary size');\n          return new Binary(\n            this.bson.subarray(offset + 1 + 4 + 4, offset + 1 + 4 + 4 + subType2BinarySize),\n            2\n          );\n        }\n\n        return new Binary(\n          this.bson.subarray(offset + 1 + 4, offset + 1 + 4 + totalBinarySize),\n          subType\n        );\n      }\n      case BSONType.date:\n        // Pretend this is correct.\n        return new Date(Number(NumberUtils.getBigInt64LE(this.bson, offset)));","sourceCodeStart":186,"sourceCodeEnd":222,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/wire_protocol/on_demand/document.ts#L186-L222","documentation":"Thrown while lazily reading a BSON Binary value of subtype 0x02 (\"old\" binary) from an OnDemandDocument. Subtype 0x02 carries an embedded inner length; when that inner length is negative (most significant bit set in the int32 LE), the bytes cannot describe a valid payload, so the parser aborts with a BSONError. This indicates the underlying BSON bytes are malformed or corrupt.","triggerScenarios":"Fires in toJSValue at src/cmap/wire_protocol/on_demand/document.ts:204 when the driver calls get(..., BSONType.binData) on an element whose subtype byte is 2 and the int32 at offset+5 is negative. Happens while parsing server responses (SDAM, command results) or any OnDemandDocument built from untrusted/corrupt BSON.","commonSituations":"Network corruption altering response bytes; a buggy server serialization path; an intermediate proxy rewriting traffic; reading a hand-crafted or truncated BSON document. Rarely seen from a healthy stable server.","solutions":["Retry the operation once (transient corruption may not recur).","Inspect network stability and any proxy between client and server.","Upgrade mongod/mongos and the driver to current patch levels.","If reproducible, capture the raw response and file a server/driver bug with the document that triggers it."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await coll.findOne({_id:1});\n} catch (e) {\n  if (e instanceof BSONError && /Negative binary type element size/.test(e.message)) {\n  }\n}","preventionTips":["Treat transient BSON parse errors as a signal to check the network path.","Keep driver and server versions aligned.","Avoid packet-inspecting middleboxes."],"tags":["bson","corruption","wire-protocol","parsing"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}