MongoDB PHP 驱动中的 BSON 编码器在将字符串长度转换为 32 位值时未进行有效性验证。当受影响的应用程序对接近 4 GiB 的字符串进行编码时,分配大小可能发生回绕(wrap),而复制操作仍使用原始长度。这会导致堆缓冲区溢出,从而破坏进程内存或导致 PHP 进程终止。要触发此问题,需要配置允许使用多吉字节(multi-gigabyte)值的非默认运行时配置。此漏洞不需要与 MongoDB 服务器交互。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | PHP Driver | 1.16.0< 1.21.11 |
affected |
2.0.0< 2.1.11 |
affected | ||
2.2.0< 2.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | PHP Driver | 1.16.0 ~ 1.21.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106433 | 8.8 HIGH | Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt |
| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107325 | 5.9 MEDIUM | Application denial of service via missing BSON array length validation in MongoDB Go Drive |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106435 | 5.1 MEDIUM | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt |
| CVE-2026-106436 | 4.8 MEDIUM | Application denial of service and data truncation via unchecked BSON append failures in Mo |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106438 | 4.0 MEDIUM | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
No comments yet