MongoDB security advisory (AV26-911)
Canada's Cyber Centre warns MongoDB Java Driver and Laravel MongoDB (PHP) have vulnerabilities fixed in versions 5.11.1 and 5.11.0.
The Canadian Centre for Cyber Security (AV26-911) reports MongoDB vulnerabilities affecting the Java Driver prior to 5.11.1 and Laravel MongoDB (PHP) prior to 5.11.0. Fixed issues include a native heap use-after-free during cancellation racing a KMS credential fetch in reactive encryption (JAVA-6276) and a query builder fix forcing literal equality when 3-arg where clauses use '=' with array values (PHPLARA-260). Administrators are urged to review the advisories and apply the updates.
MongoDB security advisory (AV26-918)
Canadian Cyber Centre advisory AV26-918 urges patching MongoDB Server vulnerability fixed in 7.0.43, 8.0.32, 8.3.11, and 9.0.1.
The Canadian Centre for Cyber Security issued advisory AV26-918 on September 14, 2026, regarding a vulnerability in MongoDB Server. Affected versions include those prior to 7.0.43, 8.0.32, 8.3.11, 9.1.0-rc0, and 9.0.1. The fix shreds collection validator constants during parsing. Users and administrators are encouraged to review MongoDB's advisory and apply updates as they become available.