MongoDB

Php Driver

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 24.09.2026 15:51:16
  • Zuletzt bearbeitet 24.09.2026 21:04:40

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command mo...

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 17:03:14
  • Zuletzt bearbeitet 10.09.2026 20:39:21

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to a...

  • EPSS 0.27%
  • Veröffentlicht 27.08.2026 18:32:26
  • Zuletzt bearbeitet 29.09.2026 19:17:04

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted t...

  • EPSS 0.35%
  • Veröffentlicht 14.05.2026 21:27:03
  • Zuletzt bearbeitet 24.09.2026 17:33:34

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

  • EPSS 0.2%
  • Veröffentlicht 18.11.2025 20:21:08
  • Zuletzt bearbeitet 07.10.2026 21:10:00

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

  • EPSS 0.26%
  • Veröffentlicht 07.08.2024 10:15:39
  • Zuletzt bearbeitet 19.09.2024 20:46:04

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of ...

  • EPSS 0.6%
  • Veröffentlicht 29.08.2023 16:15:08
  • Zuletzt bearbeitet 03.11.2025 20:15:47

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are ...