CVE-2026-106432 — The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation.
Description
The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.
CVSS v4.0 base metrics
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLow severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
Low
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Related threats
same CWE or vendorCVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107224 · 1d ago
CVE-2026-47539 — NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conv…
CVE-2026-47539 · 8d ago
CVE-2026-47508 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion…
CVE-2026-47508 · 8d ago
CVE-2026-98049 — In the Linux kernel, the following vulnerability has been resolved: bpf: zero extend the result of an arena 32-bit cmpxchg bpf_convert_ctx_access…
CVE-2026-98049 · 13d ago
CVE-2026-88387 — LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType).
CVE-2026-88387 · 14d ago
CVE-2026-88367 — NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization.
CVE-2026-88367 · 14d ago