MongoDB security advisory (AV26-911)
Canada's Cyber Centre warns MongoDB Java Driver and Laravel MongoDB (PHP) have vulnerabilities fixed in versions 5.11.1 and 5.11.0.
The Canadian Centre for Cyber Security (AV26-911) reports MongoDB vulnerabilities affecting the Java Driver prior to 5.11.1 and Laravel MongoDB (PHP) prior to 5.11.0. Fixed issues include a native heap use-after-free during cancellation racing a KMS credential fetch in reactive encryption (JAVA-6276) and a query builder fix forcing literal equality when 3-arg where clauses use '=' with array values (PHPLARA-260). Administrators are urged to review the advisories and apply the updates.
- Java Driver versions prior to 5.11.1 affected via use-after-free (JAVA-6276)
- Laravel MongoDB PHP versions prior to 5.11.0 affected (PHPLARA-260)
- Canadian Cyber Centre urges administrators to apply available updates
Full article85 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-911
Date: September 11, 2026
As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products:
- Java Driver
- Prior to 5.11.1
- Laravel MongoDB (PHP)
- Prior to 5.11.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory-av26-911