CVE-2026-6811EPSS p28.3%

CVE-2026-6811CVE-2026-6811

mongodb / php_driver

Description

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

Scoring

CVSS 5.9 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS0.37% probability of exploitation · percentile 28.3% · 2026-10-05T12:00:23Z
Last modified2026-09-24
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.