highCVSS 8.1Vulnerability
CVE-2026-81525
### Impact Passing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. ### Patches Fixed in PHP library 1.21.4 and 2.4.1. ### Workarounds Validate database and collection names prior to passing into APIs.
Properties
- severity
- high
- summary
- mongodb: Reject "." and NUL bytes in database and collection names
- epss_score
- 0.00273
- cvss_score
- 8.1
- ghsa_published
- 2026-09-08T21:27:42Z
- source_url
- https://github.com/advisories/GHSA-65fr-j4p9-vc33
- ghsa_updated
- 2026-09-08T21:27:45Z
- ghsa_id
- GHSA-65fr-j4p9-vc33
- cve_id
- CVE-2026-81525
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.19379
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]composer/mongodb/mongodb
AFFECTS (1)
→[Software]composer/mongodb/mongodb
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements in Data Query Logic
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph