An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound during query planning, and the resulting exhaustion terminates the server process. This may result in a denial of service affecting all databases served by the affected node.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-128253 | Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-08 17:18
Updated : 2026-09-14 17:26
NVD link : CVE-2026-82076
Mitre link : CVE-2026-82076
CVE.ORG link : CVE-2026-82076
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-190
Integer Overflow or Wraparound
