6.9
CVE-2026-84968
- EPSS 0.2%
- Veröffentlicht 03.09.2026 17:03:14
- Zuletzt bearbeitet 10.09.2026 20:39:21
- Erkennungen
Heap out-of-bounds read via corrupt nested BSON in field path error message
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ Php Driver SwPlatform mongodb Version >= 1.15.0 < 1.21.9
MongoDB ≫ Php Driver SwPlatform mongodb Version >= 2.0.0 < 2.1.9
MongoDB ≫ Php Driver SwPlatform mongodb Version >= 2.2.0 < 2.5.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MongoDb | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| MongoDb | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://jira.mongodb.org/browse/PHPC-2744