MongoDB PHP 驱动中的 BSON 编码器在文档超过 libbson 的大小限制时,未检查某些函数的返回值。这可能导致编码器进入无效状态。任何未经授权的攻击者,若能诱导受影响的应用程序对异常庞大的数据结构进行编码,即可导致 PHP 工作进程终止,或使生成的文档中遗漏部分字段。此漏洞无需连接 MongoDB 服务器,也无需进行数据库认证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | PHP Driver | 1.3.0< 1.21.11 |
affected |
2.0.0< 2.1.11 |
affected | ||
2.2.0< 2.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | PHP Driver | 1.3.0 ~ 1.21.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106433 | 8.8 HIGH | Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt |
| CVE-2026-106429 | 6.5 MEDIUM | Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt |
| CVE-2026-106437 | 6.2 MEDIUM | Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver |
| CVE-2026-106430 | 5.9 MEDIUM | Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver |
| CVE-2026-107325 | 5.9 MEDIUM | Application denial of service via missing BSON array length validation in MongoDB Go Drive |
| CVE-2026-107324 | 5.9 MEDIUM | Application denial of service via integer overflow in BSON value-length validation in Mong |
| CVE-2026-106431 | 5.7 MEDIUM | One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver |
| CVE-2026-106435 | 5.1 MEDIUM | Application denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Pyt |
| CVE-2026-106434 | 4.3 MEDIUM | Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt |
| CVE-2026-106438 | 4.0 MEDIUM | Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver |
| CVE-2026-106428 | 3.7 LOW | Out-of-bounds read in SCRAM response parsing in MongoDB C Driver |
| CVE-2026-106432 | 3.6 LOW | Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver |
No comments yet