7.1

CVE-2026-82054

Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of Service

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ MongoDB Version >= 7.0.0 < 7.0.41
MongoDB ≫ MongoDB Version >= 8.0.0 < 8.0.30
MongoDB ≫ MongoDB Version >= 8.2.0 <= 8.2.12
MongoDB ≫ MongoDB Version >= 8.3.0 < 8.3.9
MongoDB ≫ MongoDB Version 9.0.0 Update alpha0 SwEdition - SwPlatform -
MongoDB ≫ MongoDB Version 9.0.0 Update alpha1 SwEdition - SwPlatform -
MongoDB ≫ MongoDB Version 9.1.0 Update alpha0 SwEdition - SwPlatform -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.213
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MongoDb 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
MongoDb 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://jira.mongodb.org/browse/SERVER-130901
Vendor Advisory
Issue Tracking