Impact
The MongoDB PHP Driver’s BSON encoder fails to verify return values after a document exceeds libbson’s size limit, potentially leaving the encoder in an invalid state. Based on the description, it is inferred that an unauthenticated attacker can force an application to encode an unusually large data structure, which may terminate the PHP worker or produce a truncated document. This results in a denial of service and loss of data integrity, affecting application availability and correctness.
Affected Systems
MongoDB PHP Driver. No specific affected versions are listed; any deployment of the driver prior to the documented fix is potentially vulnerable and should be reviewed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.3, indicating moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector requires an attacker who can send a large payload to an application using the driver; because no authentication or database connection is required, the effect can be triggered by any user interacting with the application.
OpenCVE Enrichment