CVE-2026-9749

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-124031 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-06-09 23:17

Updated : 2026-07-23 09:10


NVD link : CVE-2026-9749

Mitre link : CVE-2026-9749

CVE.ORG link : CVE-2026-9749


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion