Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106432— Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver

Quick assessment

Affected
MongoDB PHP Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MongoDB PHP 驱动中的 BSON 编码器在将字符串长度转换为 32 位值时未进行有效性验证。当受影响的应用程序对接近 4 GiB 的字符串进行编码时,分配大小可能发生回绕(wrap),而复制操作仍使用原始长度。这会导致堆缓冲区溢出,从而破坏进程内存或导致 PHP 进程终止。要触发此问题,需要配置允许使用多吉字节(multi-gigabyte)值的非默认运行时配置。此漏洞不需要与 MongoDB 服务器交互。

CVSS 3.6 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
MongoDB PHP Driver 1.16.0< 1.21.11 affected
2.0.0< 2.1.11 affected
2.2.0< 2.5.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106432

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver
Source: CVE Program / CVE List V5
Vulnerability Description
The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
数值类型间的不正确转换
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB PHP Driver 1.16.0 ~ 1.21.11 -

II. Public POCs for CVE-2026-106432

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106432

请登录查看更多情报信息。

Other References for CVE-2026-106432 (1)

Same Patch Batch · MongoDB · 2026-10-08 · 13 CVEs total

CVE-2026-106433 8.8 HIGH Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt
CVE-2026-106429 6.5 MEDIUM Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt
CVE-2026-106437 6.2 MEDIUM Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver
CVE-2026-106430 5.9 MEDIUM Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver
CVE-2026-107325 5.9 MEDIUM Application denial of service via missing BSON array length validation in MongoDB Go Drive
CVE-2026-107324 5.9 MEDIUM Application denial of service via integer overflow in BSON value-length validation in Mong
CVE-2026-106431 5.7 MEDIUM One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver
CVE-2026-106435 5.1 MEDIUM Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt
CVE-2026-106436 4.8 MEDIUM Application denial of service and data truncation via unchecked BSON append failures in Mo
CVE-2026-106434 4.3 MEDIUM Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt
CVE-2026-106438 4.0 MEDIUM Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver
CVE-2026-106428 3.7 LOW Out-of-bounds read in SCRAM response parsing in MongoDB C Driver

IV. Related Vulnerabilities

V. Comments for CVE-2026-106432

No comments yet


Leave a comment