THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-65fr-j4p9-vc33 (high) — mongodb: Reject "." and NUL bytes in database and collection names

[GHSA] GHSA-65fr-j4p9-vc33 (high) — mongodb: Reject "." and NUL bytes in database and collection names

medgithub_advisoriesPublished 2026-09-08

GHSA-65fr-j4p9-vc33 Severity: high CVE: CVE-2026-81525

mongodb: Reject "." and NUL bytes in database and collection names

### Impact Passing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified.

### Patches Fixed in PHP library 1.21.4 and 2.4.1.

### Workarounds Validate database and collection names prior to passing

Indicators of compromise

Original source: https://github.com/advisories/GHSA-65fr-j4p9-vc33