在 Laravel 的 MongoDB 集成模块中,缓存锁实现的查询逻辑对特殊元素的转义处理不当,可能导致调用者提供的锁持有者(owner)值被当作聚合表达式而非字面量进行求值。具有认证权限且能够影响应用程序在获取或恢复锁时所使用的持有者值的用户,可能接管由其他进程持有的锁,或使其提前过期,从而导致重复或冲突的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Laravel MongoDB (PHP) | 4.3.0 ~ 5.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96749 | 8.4 HIGH | Heap out-of-bounds write via signed size overflow in BSON document encoding |
| CVE-2026-96750 | 7.1 HIGH | Shell script injection via server-supplied database name in Open MongoDB shell |
| CVE-2026-96746 | 6.5 MEDIUM | Heap buffer overflow via mid-scan command list growth in client topology monitoring |
| CVE-2026-96748 | 6.5 MEDIUM | Connection redirection via percent-encoded delimiter injection in connection string hosts |
| CVE-2026-96745 | 5.6 MEDIUM | PHP object injection via unsuppressible __pclass class inference in command monitoring eve |
| CVE-2026-96747 | 5.0 MEDIUM | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt |
No comments yet