CVE-2026-84968

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.
References
Link Resource
https://jira.mongodb.org/browse/PHPC-2744 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*
cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*
cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*

History

No history.

Information

Published : 2026-09-03 18:17

Updated : 2026-09-10 20:39


NVD link : CVE-2026-84968

Mitre link : CVE-2026-84968

CVE.ORG link : CVE-2026-84968


JSON object : View

Products Affected

mongodb

  • php_driver
CWE
CWE-125

Out-of-bounds Read