๐Ÿ” CVE Alert

CVE-2026-84968

MEDIUM 5.3

Heap out-of-bounds read via corrupt nested BSON in field path error message

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

CWE CWE-125
Vendor mongodb
Product php driver
Ecosystems
Industries
Technology
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for mongodb php driver

Be the first to know when new medium vulnerabilities affecting mongodb php driver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

MongoDB / PHP Driver
1.15.0 < 1.21.8 2.0.0 < 2.5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
jira.mongodb.org: https://jira.mongodb.org/browse/PHPC-2744