CVE-2026-6811General(mongodb / php_driver)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php_driver

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
php_driver

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-07-22: 1Technical Details · 2026-05-14: 1Technical Details · 2026-07-22: 105-1407-22
Signal classification1 categories
General
2100.0%
Referenced assets18 URLs
Full discourse2 posts
  • Jan Guldentops@JanGuldentops
    General

    Alle individuele kwetsbaarheden uit de post met hun rechtstreekse link naar de European Vulnerability Database (EUVD) van ENISA: Active Directory Federation Services privilege escalation (CVE-2026-56155): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-56155 BitLocker encryptieomzeiling (CVE-2026-50661): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-50661 Remote Desktop kwetsbaarheid (CVE-2026-56190): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-56190 Hyper-V virtual machine escape (CVE-2026-57092): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-57092 Cisco VoIP kwetsbaarheid (CVE-2026-20150): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20150 Cisco SD-WAN kwetsbaarheid (CVE-2026-20182): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20182 Google Chrome bug 1 (CVE-2026-6811): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6811 Google Chrome bug 2 (CVE-2026-6812): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6812 Google Chrome bug 3 (CVE-2026-6813): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-6813 Curl kwetsbaarheden range (CVE-2026-22834 t/m CVE-2026-22851): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-22834 Fortinet FortiSandbox securitylek 1 (CVE-2026-25089): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-25089 Fortinet FortiSandbox securitylek 2 (CVE-2026-39808): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-39808 SonicWall SMA1000 server-side request forgery (CVE-2026-15409): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-15409 SonicWall SMA1000 code injection en privesc (CVE-2026-15410): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-15410 WordPress zero day (CVE-2026-63030): https://euvd.enisa.europa.eu/vulnerability/CVE-2026-63030 Linux Kernel ip6_tunnel RCE ( CVE-2026-43037) https://euvd.enisa.europa.eu/vulnerability/CVE-2026-43037 • • Linux kernel XFRM IPSEc ESP bug ( CVE-2026-43284 ) https://euvd.enisa.europa.eu/vulnerability/CVE-2026-43285

    Post summary

    The post enumerates several CVEs with direct EUVD links and basic vulnerability titles, but it does not include PoC, exploit code, active exploitation reports, or patches.

    00000171
    1.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6811 Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the so… https://www.cve.org/CVERecord?id=CVE-2026-6811

    Post summary

    The tweet announces that CVE-2026-6811 is a stack exhaustion issue in the MongoDB PHP driver triggered by deeply nested BSON documents, without any exploitation or patch details.

    00000172
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbphp_driver-mongodb-

Explore more