6
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
Basic Information
ID
CVE-2026-6811
Source
mongodb
Published
May 14, 2026 at 21:27
Affected Product
Vendor
MongoDB Inc.
Product
PHP Driver
Version
1.21.5
Affected Versions
MongoDB Inc. PHP Driver 1.21.5
MongoDB Inc. PHP Driver 2.1.8
MongoDB Inc. PHP Driver 2.1.8