CVE-2026-106432
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Overflow in MongoDB PHP Driver BSON Encoder

Vulnerability report for CVE-2026-106432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
MongoDB PHP Driver 1.16.0
MongoDB PHP Driver 2.0.0
MongoDB PHP Driver 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-681 When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The BSON encoder in the MongoDB PHP Driver has a flaw where it converts a string length to a 32-bit value without proper validation. When encoding a string near 4 GiB, the allocation size may wrap around while the copy operation uses the original length, causing a heap buffer overflow. This can corrupt memory or crash the PHP process. The issue requires a non-default runtime setting allowing multi-gigabyte values.

Detection Guidance

This vulnerability requires a non-default runtime configuration allowing multi-gigabyte string values. Detection involves checking PHP applications using the MongoDB PHP Driver for heap corruption or process termination when processing large strings. Monitor logs for crashes or memory corruption errors in PHP processes.

Impact Analysis

This vulnerability can lead to memory corruption or application crashes if an affected system processes strings near 4 GiB. It may allow attackers to execute arbitrary code or cause denial-of-service conditions. The impact is limited to systems with non-default configurations permitting large string values.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized memory corruption or process termination in PHP applications using the MongoDB PHP Driver. If exploited, it may lead to data integrity issues or denial of service, which could violate confidentiality or availability requirements under these regulations.

Mitigation Strategies

Immediately update the MongoDB PHP Driver to the latest version. Disable or restrict runtime configurations that permit multi-gigabyte string values. Review and restrict user input sizes in PHP applications to prevent large string allocations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart