CVE-2026-6811

EUVD-2026-30490
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mongodbCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mongodbphp_driver
1.21.5
CNA
mongodbphp_driver
2.1.8
CNA
Debian logo
Debian Releases
Debian Product
Codename
php-mongodb
bookworm
no-dsa
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa