CVE-2026-6811: MongoDB PHP Driver

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

Affected products

  • MongoDB PHP Driver: from 1.21.0, before 1.21.5 (fixed in 1.21.5); from 2.1.0, before 2.1.8 (fixed in 2.1.8)

Published 2026-05-14. Last modified 2026-09-24.