Description
The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. This can leave the encoder in an invalid state. An unauthenticated actor who can cause an affected application to encode an unusually large data structure can terminate the PHP worker or cause the resulting document to omit fields. No MongoDB server connection or database authentication is required.
Published: 2026-10-08
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The MongoDB PHP Driver’s BSON encoder fails to verify return values after a document exceeds libbson’s size limit, potentially leaving the encoder in an invalid state. Based on the description, it is inferred that an unauthenticated attacker can force an application to encode an unusually large data structure, which may terminate the PHP worker or produce a truncated document. This results in a denial of service and loss of data integrity, affecting application availability and correctness.

Affected Systems

MongoDB PHP Driver. No specific affected versions are listed; any deployment of the driver prior to the documented fix is potentially vulnerable and should be reviewed.

Risk and Exploitability

The vulnerability has a CVSS score of 6.3, indicating moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector requires an attacker who can send a large payload to an application using the driver; because no authentication or database connection is required, the effect can be triggered by any user interacting with the application.

Generated by OpenCVE AI on October 8, 2026 at 20:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MongoDB PHP Driver to a version that implements proper error handling for BSON append operations.
  • Enforce input size limits on data structures before they are passed to the driver to prevent exceeding libbson size limits.
  • Validate that each BSON encoding operation succeeds before using the resulting document and gracefully handle any errors that occur.

Generated by OpenCVE AI on October 8, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb php Driver
Vendors & Products Mongodb
Mongodb php Driver

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. This can leave the encoder in an invalid state. An unauthenticated actor who can cause an affected application to encode an unusually large data structure can terminate the PHP worker or cause the resulting document to omit fields. No MongoDB server connection or database authentication is required.
Title Application denial of service and data truncation via unchecked BSON append failures in MongoDB PHP Driver
Weaknesses CWE-252
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Php Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-10-08T19:52:06.877Z

Reserved: 2026-10-06T16:40:35.017Z

Link: CVE-2026-106436

cve-icon Vulnrichment

Updated: 2026-10-08T19:52:03.403Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:31.087

Modified: 2026-10-08T20:49:23.240

Link: CVE-2026-106436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:14Z

Weaknesses