Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/PHPC-2744 |
|
Thu, 03 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb php Driver |
|
| Vendors & Products |
Mongodb
Mongodb php Driver |
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents. | |
| Title | Heap out-of-bounds read via corrupt nested BSON in field path error message | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-03T17:32:29.660Z
Reserved: 2026-09-02T17:58:52.742Z
Link: CVE-2026-84968
Updated: 2026-09-03T17:31:27.205Z
Status : Received
Published: 2026-09-03T18:17:33.010
Modified: 2026-09-03T18:17:33.010
Link: CVE-2026-84968
No data.
OpenCVE Enrichment
Updated: 2026-09-03T18:30:04Z
