CVE-2026-6811

NameCVE-2026-6811
DescriptionStack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-mongodb (PTS)bullseye1.9.0+1.7.5-2vulnerable
bookworm1.15.0+1.11.1+1.9.2+1.7.5-1vulnerable
trixie2.0.0-1vulnerable
forky, sid2.1.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-mongodbsource(unstable)(unfixed)

Notes

https://jira.mongodb.org/browse/PHPC-2636
Fixed by: https://github.com/mongodb/mongo-php-driver/commit/2060beb85a041182550d022ec223783ffdaf6ec8 (.21.5, 2.1.8)

Search for package or bug name: Reporting problems