#1148966 php-mongodb: CVE-2026-96745

Package:
src:php-mongodb
Source:
src:php-mongodb
Submitter:
Salvatore Bonaccorso
Date:
2026-10-01 08:23:02 UTC
Severity:
normal
Tags:
#1148966#5
Date:
2026-09-25 19:11:48 UTC
From:
To:
Hi,

The following vulnerability was published for php-mongodb.

CVE-2026-96745[0]:
| Deserialization of untrusted data in the command monitoring support
| of the MongoDB PHP Driver can cause class names embedded in document
| content to be honored when the driver builds monitoring event
| objects. When an application registers a command monitoring
| subscriber and includes untrusted data in a database operation, an
| unauthenticated party who controls that data may cause an
| application class implementing the driver's persistable interface to
| be instantiated and its unserialization method invoked with the
| supplied data. The resulting impact depends on the classes available
| in the application.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-96745
https://www.cve.org/CVERecord?id=CVE-2026-96745
[1] https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
[2] https://jira.mongodb.org/browse/PHPC-2743
[3] https://github.com/mongodb/mongo-php-driver/pull/2115

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148966#10
Date:
2026-09-25 19:19:06 UTC
From:
To:
Salvatore, would it be feasible to pick the new upstream version or do you
want me to cherry-pick the patches for the CVEs? The deb.sury.org <http://deb.sury.org/> does
have 2.5.2 since Wednesday and no regression reports were reported.

Ondrej
--
Ondřej Surý (He/Him)
ondrej@sury.org

A gentle nudge is always appreciated if I take a little longer to reply.

#1148966#15
Date:
2026-09-26 08:35:44 UTC
From:
To:
Hi Ondrej,

I think that was only fixed in 2.5.3 upstream for the given CVE.

There are currently 3 known open issues according to
https://security-tracker.debian.org/tracker/source-package/php-mongodb
but we have not yet evaluated in our backlog if they warrant a DSA.

Let's followup on team@s.d.o with that.

Regards,
Salvatore

#1148966#20
Date:
2026-10-01 08:21:29 UTC
From:
To:
Source: php-mongodb
Source-Version: 2.5.3-1