BSON Encoder Flaw in MongoDB PHP Driver Allows Unchecked Document Size Handling
CVE-2026-106436

6.3MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 October 2026

What is CVE-2026-106436?

The BSON encoder within the MongoDB PHP Driver has a flaw where it fails to validate certain return values when a document exceeds the size limit defined by libbson. This oversight can lead to the encoder becoming invalidated under specific conditions. An unauthenticated attacker can exploit this by submitting unusually large data structures, which may lead to termination of the PHP worker or result in omitting fields from the encoded document. This issue does not require any MongoDB server connection or database credentials, making it particularly concerning for applications that heavily rely on this driver.

Affected Version(s)

PHP Driver 1.3.0 < 1.21.11

PHP Driver 2.0.0 < 2.1.11

PHP Driver 2.2.0 < 2.5.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.