mongodb/node-mongodb-native · error · BSONError

Negative binary type element size found for subtype 0x02

Error message

Negative binary type element size found for subtype 0x02

What it means

Thrown while lazily reading a BSON Binary value of subtype 0x02 ("old" binary) from an OnDemandDocument. Subtype 0x02 carries an embedded inner length; when that inner length is negative (most significant bit set in the int32 LE), the bytes cannot describe a valid payload, so the parser aborts with a BSONError. This indicates the underlying BSON bytes are malformed or corrupt.

Solutions

  1. Retry the operation once (transient corruption may not recur).
  2. Inspect network stability and any proxy between client and server.
  3. Upgrade mongod/mongos and the driver to current patch levels.
  4. If reproducible, capture the raw response and file a server/driver bug with the document that triggers it.
Defensive patterns

Strategy: retry

Try / catch

try {
  await coll.findOne({_id:1});
} catch (e) {
  if (e instanceof BSONError && /Negative binary type element size/.test(e.message)) {
  }
}

Prevention

When it happens

Trigger: Fires in toJSValue at src/cmap/wire_protocol/on_demand/document.ts:204 when the driver calls get(..., BSONType.binData) on an element whose subtype byte is 2 and the int32 at offset+5 is negative. Happens while parsing server responses (SDAM, command results) or any OnDemandDocument built from untrusted/corrupt BSON.

Common situations: Network corruption altering response bytes; a buggy server serialization path; an intermediate proxy rewriting traffic; reading a hand-crafted or truncated BSON document. Rarely seen from a healthy stable server.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/2bfd018e0aba3f98. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/wire_protocol/on_demand/document.ts:204

        return NumberUtils.getInt32LE(this.bson, offset);
      case BSONType.long:
        return NumberUtils.getBigInt64LE(this.bson, offset);
      case BSONType.bool:
        return Boolean(this.bson[offset]);
      case BSONType.objectId:
        return new ObjectId(this.bson.subarray(offset, offset + 12));
      case BSONType.timestamp:
        return new Timestamp(NumberUtils.getBigInt64LE(this.bson, offset));
      case BSONType.string:
        return ByteUtils.toUTF8(this.bson, offset + 4, offset + length - 1, false);
      case BSONType.binData: {
        const totalBinarySize = NumberUtils.getInt32LE(this.bson, offset);
        const subType = this.bson[offset + 4];

        if (subType === 2) {
          const subType2BinarySize = NumberUtils.getInt32LE(this.bson, offset + 1 + 4);
          if (subType2BinarySize < 0)
            throw new BSONError('Negative binary type element size found for subtype 0x02');
          if (subType2BinarySize > totalBinarySize - 4)
            throw new BSONError('Binary type with subtype 0x02 contains too long binary size');
          if (subType2BinarySize < totalBinarySize - 4)
            throw new BSONError('Binary type with subtype 0x02 contains too short binary size');
          return new Binary(
            this.bson.subarray(offset + 1 + 4 + 4, offset + 1 + 4 + 4 + subType2BinarySize),
            2
          );
        }

        return new Binary(
          this.bson.subarray(offset + 1 + 4, offset + 1 + 4 + totalBinarySize),
          subType
        );
      }
      case BSONType.date:
        // Pretend this is correct.
        return new Date(Number(NumberUtils.getBigInt64LE(this.bson, offset)));

View on GitHub (pinned to dce7939f86)