MongoDB PHP 驱动程序的命令监控功能中存在对不可信数据的反序列化漏洞。当驱动程序构建监控事件对象时,可能会识别并处理嵌入在文档内容中的类名。如果应用程序注册了命令监控订阅者,并在数据库操作中使用了包含不可信数据的内容,则不受身份验证的控制该数据的攻击者可能导致应用程序中实现驱动程序可持久化接口的类被实例化,并以其提供的数据调用反序列化方法。最终的影响取决于应用程序中可用的类。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | PHP Driver | 0 ~ 1.21.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96749 | 8.4 HIGH | Heap out-of-bounds write via signed size overflow in BSON document encoding |
| CVE-2026-96750 | 7.1 HIGH | Shell script injection via server-supplied database name in Open MongoDB shell |
| CVE-2026-96744 | 7.1 HIGH | Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB |
| CVE-2026-96746 | 6.5 MEDIUM | Heap buffer overflow via mid-scan command list growth in client topology monitoring |
| CVE-2026-96748 | 6.5 MEDIUM | Connection redirection via percent-encoded delimiter injection in connection string hosts |
| CVE-2026-96747 | 5.0 MEDIUM | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt |
No comments yet