CVE-2026-106436
Awaiting Analysis Awaiting Analysis - Queue

BSON Size Limit Handling Flaw in MongoDB PHP Driver

Vulnerability report for CVE-2026-106436, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MongoDB, Inc.

Description

The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. This can leave the encoder in an invalid state. An unauthenticated actor who can cause an affected application to encode an unusually large data structure can terminate the PHP worker or cause the resulting document to omit fields. No MongoDB server connection or database authentication is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
MongoDB PHP Driver 1.3.0
MongoDB PHP Driver 2.0.0
MongoDB PHP Driver 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-252 The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The BSON encoder in the MongoDB PHP Driver fails to validate return values when a document exceeds size limits. This leaves the encoder in an invalid state. An attacker can exploit this by causing the application to encode an abnormally large data structure, which may terminate the PHP worker or cause the document to omit certain fields without requiring a MongoDB server connection or authentication.

Detection Guidance

This vulnerability can be detected by monitoring PHP applications using the MongoDB PHP Driver for crashes or unexpected behavior when encoding large BSON documents. Check PHP worker logs for termination events or missing fields in encoded documents. No specific commands are provided in the context.

Impact Analysis

This vulnerability can lead to denial of service by crashing PHP workers or cause data integrity issues by omitting fields in encoded documents. It may disrupt application functionality and require manual intervention to restore normal operations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized data omission or application termination. If an attacker exploits this flaw to omit fields in a document, it may result in incomplete or inaccurate data storage, which could violate data integrity requirements under these regulations. Additionally, unauthorized termination of PHP workers might disrupt logging or audit processes, further affecting compliance.

Mitigation Strategies

Update the MongoDB PHP Driver to the latest version that fixes the BSON encoder issue. Review and restrict input sizes in applications to prevent encoding unusually large data structures.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart