Hi,
The following vulnerability was published for php-mongodb.
CVE-2026-96745[0]:
| Deserialization of untrusted data in the command monitoring support
| of the MongoDB PHP Driver can cause class names embedded in document
| content to be honored when the driver builds monitoring event
| objects. When an application registers a command monitoring
| subscriber and includes untrusted data in a database operation, an
| unauthenticated party who controls that data may cause an
| application class implementing the driver's persistable interface to
| be instantiated and its unserialization method invoked with the
| supplied data. The resulting impact depends on the classes available
| in the application.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-96745
https://www.cve.org/CVERecord?id=CVE-2026-96745
[1] https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
[2] https://jira.mongodb.org/browse/PHPC-2743
[3] https://github.com/mongodb/mongo-php-driver/pull/2115
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore