CVE-2026-106436 — The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit.
Description
The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. This can leave the encoder in an invalid state. An unauthenticated actor who can cause an affected application to encode an unusually large data structure can terminate the PHP worker or cause the resulting document to omit fields. No MongoDB server connection or database authentication is required.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
Low
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Related threats
same CWE or vendorCVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…
CVE-2026-18397 · 7d ago
CVE-2026-95316 — Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program.
CVE-2026-95316 · 9d ago
CVE-2026-67409 — RabbitMQ is a messaging and streaming broker.
CVE-2026-67409 · 13d ago
CVE-2026-71180 — Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability.
CVE-2026-71180 · 22d ago
CVE-2026-90648 — wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack.
CVE-2026-90648 · 26d ago
CVE-2026-86749 — Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages().
CVE-2026-86749 · 29d ago