Intel

AIKIDO-2026-561128

mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read

Out-of-Bounds ReadCVE-2026-84968 Published 2 days ago

69

Medium Risk

This Affects:

PHPmongodb/mongodb-extension
1.15.0 - 1.21.7
Fixed in 1.21.8
2.0.0 - 2.1.8
Fixed in 2.1.9
2.2.0 - 2.5.0
Fixed in 2.5.1
Are you affected? Scan for Free

TL;DR

MongoDB's PHP driver builds a dotted field path string for exception messages about corrupt BSON from an array of field path elements. When the nesting depth is a multiple of that array's allocation step, the loop reads one element past the end of the allocation and copies adjacent heap memory into the error message. Decoding a corrupt or malformed BSON document at one of these depths triggers the out-of-bounds read and exposes uninitialized heap contents to the caller. The fix bounds the loop by both the array's allocated size and its logical size.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range, and you decode corrupt or externally supplied BSON data that includes deeply nested field structures.

Background info

mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read in versions 1.15.0 - 1.21.7, 2.0.0 - 2.1.8 and 2.2.0 - 2.5.0.

How to fix this

Upgrade the mongodb/mongodb-extension and/or the mongodb library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform