GHSA-pv5p-66r3-9fq9HighCVSS 6.6

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.

🔗 References (3)