Junglewise Threat Intelligence

CVE-2026-84968: MongoDB PHP Driver out-of-bounds read in BSON decoding

CVE-2026-84968 · Severity: medium · CVSS 5.3 · Published 2026-09-03

Technologies: MongoDB PHP Driver. Vendors: MongoDB.

Executive brief

The MongoDB PHP driver contains a flaw in how it processes corrupted data format (BSON). When an application receives specially crafted input, the driver may read memory beyond its intended bounds and leak that data in error messages sent back to the application, potentially exposing sensitive information from the server's memory.

Technical details

An out-of-bounds read vulnerability exists in the BSON decoding component of the MongoDB PHP driver. The vulnerability is triggered when the driver processes malformed BSON input without proper bounds checking. An unauthenticated attacker can supply specially crafted BSON data to cause an out-of-bounds memory read, with adjacent process memory contents copied into error messages returned to application code. This allows limited disclosure of unintended memory contents. The vulnerability has been fixed in versions 2.5.2, 1.21.9, and 2.1.9.

Affected products

  • MongoDB PHP Driver before 1.21.9, before 2.1.9, before 2.5.2

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Fixed in versions 1.21.9, 2.1.9, and 2.5.2

References

Related threats