Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NMEDIUM: 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
1.21.5 (semver)
affected
2.1.8 (semver)
affected
Description
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
Problem types
CWE-674 Uncontrolled Recursion
Product status
1.21.5 (semver)
2.1.8 (semver)
References
jira.mongodb.org/browse/PHPC-2636