{"id":"CVE-2026-84968","summary":"Heap out-of-bounds read via corrupt nested BSON in field path error message","details":"An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.","modified":"2026-09-12T03:47:20.843400492Z","published":"2026-09-03T17:03:14.139Z","database_specific":{"cna_assigner":"mongodb","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84968.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.15.0"},{"fixed":"1.21.8"},{"introduced":"2.0.0"},{"fixed":"2.1.9"},{"introduced":"2.2.0"},{"fixed":"2.5.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/PHPC-2744"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84968.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84968"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo-php-driver","events":[{"introduced":"7a73cdfd4399962b46ecf8a823c0a23e6d77eed8"},{"fixed":"d67f76efe90a22b231ad6ff652a548bd65b2e5dc"},{"introduced":"5a7adc35edf11107e8266146413d69b83de33d3f"},{"fixed":"152dcc55ebc91d8ea9a786a190b81763664adff8"},{"introduced":"c63f6f23f087a5c33d70e47539372f2d8e429343"},{"fixed":"365aabbed6a6ba1f6a126d6c876d87cdf9f61a82"}],"database_specific":{"cpe":"cpe:2.3:a:mongodb:php_driver:*:*:*:*:*:mongodb:*:*","extracted_events":[{"introduced":"1.15.0"},{"fixed":"1.21.9"},{"introduced":"2.0.0"},{"fixed":"2.1.9"},{"introduced":"2.2.0"},{"fixed":"2.5.2"}],"source":"CPE_RANGE"}}],"versions":["2.5.1","1.21.8","2.5.0","1.21.7","1.21.6","2.2.0","2.1.8","1.21.5","2.1.7","1.21.4","2.1.4","2.1.3","1.21.2","2.1.2","2.1.1","1.21.1","2.1.0","1.21.0","1.18.0","1.17.0","1.15.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84968.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}