CVE-2026-84968: MongoDB PHP Driver

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

Affected products

  • MongoDB PHP Driver: from 1.15.0, before 1.21.9 (fixed in 1.21.9); from 2.0.0, before 2.1.9 (fixed in 2.1.9); from 2.2.0, before 2.5.2 (fixed in 2.5.2)

Published 2026-09-03. Last modified 2026-09-10.