7.1

CVE-2026-18688

Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ MongoDB Version >= 7.0.0 < 7.0.40
MongoDB ≫ MongoDB Version >= 8.0.0 < 8.0.29
MongoDB ≫ MongoDB Version >= 8.2.0 <= 8.2.12
MongoDB ≫ MongoDB Version >= 8.3.0 < 8.3.8
MongoDB ≫ MongoDB Version 9.0.0 Update alpha0 SwEdition - SwPlatform -
MongoDB ≫ MongoDB Version 9.0.0 Update alpha1 SwEdition - SwPlatform -
MongoDB ≫ MongoDB Version 9.1.0 Update alpha0 SwEdition - SwPlatform -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.189
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MongoDb 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
MongoDb 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://jira.mongodb.org/browse/SERVER-129617
Vendor Advisory
Issue Tracking