MongoDB released fixes for two vulnerabilities affecting the Java Driver and the Laravel MongoDB PHP integration. JAVA-6276 affects Java Driver releases before 5.11.1 and is a native-heap use-after-free condition in reactive encryption, triggered when cancellation races with retrieval of Key Management Service (KMS) credentials.
PHPLARA-260 affects Laravel MongoDB versions before 5.11.0 and involves three-argument query-builder where calls that use = with an array value; the fix enforces literal equality for this condition. Organizations using the affected components should upgrade to Java Driver 5.11.1 or later and Laravel MongoDB 5.11.0 or later, and review MongoDB advisory guidance.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Guyana National CIRT issued an advisory covering JAVA-6276 and PHPLARA-260, recommending upgrades to MongoDB Java Driver 5.11.1 or later and Laravel MongoDB 5.11.0 or later.
The Canadian Centre for Cyber Security published advisory AV26-911, directing users and administrators to review MongoDB's advisory material and apply available updates for the affected Java Driver and Laravel MongoDB products.
MongoDB reported vulnerabilities affecting Java Driver versions before 5.11.1 and Laravel MongoDB (PHP) versions before 5.11.0. JAVA-6276 is a native-heap use-after-free caused by a cancellation race with KMS credential retrieval in reactive encryption, while PHPLARA-260 affects array-value handling in three-argument query-builder where clauses using '='.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.