GHSA-rf6p-955q-5j7wHighCVSS 7.1

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.

🔗 References (3)