BSON Encoder Flaw in MongoDB PHP Driver Allows Unchecked Document Size Handling
CVE-2026-106436
6.3MEDIUM
What is CVE-2026-106436?
The BSON encoder within the MongoDB PHP Driver has a flaw where it fails to validate certain return values when a document exceeds the size limit defined by libbson. This oversight can lead to the encoder becoming invalidated under specific conditions. An unauthenticated attacker can exploit this by submitting unusually large data structures, which may lead to termination of the PHP worker or result in omitting fields from the encoded document. This issue does not require any MongoDB server connection or database credentials, making it particularly concerning for applications that heavily rely on this driver.
Affected Version(s)
PHP Driver 1.3.0 < 1.21.11
PHP Driver 2.0.0 < 2.1.11
PHP Driver 2.2.0 < 2.5.4