Heap Buffer Overflow in MongoDB PHP Driver Affects PHP Applications
CVE-2026-106432
2LOW
What is CVE-2026-106432?
The BSON encoder in the MongoDB PHP Driver is susceptible to a heap buffer overflow due to the improper conversion of string lengths to 32-bit values without adequate validation. This vulnerability can be triggered in applications that encode strings close to 4 GiB in size. Specifically, when the allocation size wraps during the copy operation, it can potentially corrupt process memory or lead to the termination of the PHP process. This issue hinges upon a non-default runtime configuration that allows multi-gigabyte values, thereby posing a risk without the need for interaction with a MongoDB server.
Affected Version(s)
PHP Driver 1.16.0 < 1.21.11
PHP Driver 2.0.0 < 2.1.11
PHP Driver 2.2.0 < 2.5.4