Description
The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.
Published: 2026-10-08
Score: 2 Low
EPSS: n/a
KEV: No
Impact: Heap Buffer Overflow
Action: Assess Impact
AI Analysis

Impact

The BSON encoder in the MongoDB PHP Driver converts a string length to a 32‑bit value without validating the size. When an application encodes a string that approaches 4 GiB, the allocated buffer size can wrap back to a small value while the copy operation still uses the original, huge length. This heap buffer overflow can corrupt process memory or cause the PHP process to terminate. The flaw exists only within the driver and does not require any interaction with a MongoDB server. The potential impact is limited to memory corruption and a crash of the PHP application.

Affected Systems

MongoDB PHP Driver is the affected product. No specific version range was provided, so any installation that includes the unpatched BSON encoder is susceptible.

Risk and Exploitability

The CVSS score of 2 indicates a low severity assessment. EPSS is not available and the flaw is not listed in CISA’s KEV catalog. Exploitation requires a runtime configuration that permits strings close to the 4‑GiB boundary; the default configuration typically mitigates this scenario. If an attacker can supply large strings to a PHP application that uses the driver, they could potentially trigger the overflow and crash the process, but a successful exploitation would not provide an attacker with code execution or persistence. The vulnerability is therefore considered low risk under typical configurations but could become more serious in a scenario where large payloads are accepted without validation.

Generated by OpenCVE AI on October 8, 2026 at 20:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB PHP Driver to the latest version that contains the fix for the BSON encoding overflow.
  • Configure the PHP runtime or application server to disallow or reject strings that approach the 4 GiB boundary, for example by setting appropriate length limits in php.ini or within the application logic.
  • Implement validation checks in the application layer to ensure that any string passed to the driver is within a safe, small size before encoding.

Generated by OpenCVE AI on October 8, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb php Driver
Vendors & Products Mongodb
Mongodb php Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.
Title Heap buffer overflow via 32-bit string-length truncation in MongoDB PHP Driver
Weaknesses CWE-681
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Php Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:51:42.949Z

Reserved: 2026-10-06T16:40:35.016Z

Link: CVE-2026-106432

cve-icon Vulnrichment

Updated: 2026-10-08T19:51:39.099Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:30.647

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:14Z

Weaknesses
  • CWE-681

    Incorrect Conversion between Numeric Types