Executive brief
The MongoDB PHP driver contains a flaw in how it processes corrupted data format (BSON). When an application receives specially crafted input, the driver may read memory beyond its intended bounds and leak that data in error messages sent back to the application, potentially exposing sensitive information from the server's memory.
Technical details
An out-of-bounds read vulnerability exists in the BSON decoding component of the MongoDB PHP driver. The vulnerability is triggered when the driver processes malformed BSON input without proper bounds checking. An unauthenticated attacker can supply specially crafted BSON data to cause an out-of-bounds memory read, with adjacent process memory contents copied into error messages returned to application code. This allows limited disclosure of unintended memory contents. The vulnerability has been fixed in versions 2.5.2, 1.21.9, and 2.1.9.
Affected products
- MongoDB PHP Driver before 1.21.9, before 2.1.9, before 2.5.2
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fixed in versions 1.21.9, 2.1.9, and 2.5.2