MongoDB security advisory (AV26-911)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial Number: AV26-911Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value [JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption Alerts | MongoDB

This version

Version
1 of 1
Recorded
September 20, 2026 19:55
Change
Initial
Content hash
24742ea263d674b34dbf6b385586d5b1
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.