CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96745

MEDIUMCVSS 5.6NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-96745 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96745

MEDIUMCVSS 5.6NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]