CVE-2026-106432

CVE-2026-106432 published: The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting...

View full NVD advisory → ← Back to CVE watch