PT-2026-40528 · Mongodb · Mongodb Server+1
CVE-2026-8199
·
Published
2026-05-13
·
Updated
2026-05-14
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MongoDB Server versions prior to 7.0.34
MongoDB Server versions prior to 8.0.23
MongoDB Server versions prior to 8.2.9
MongoDB Server versions prior to 8.3.2
Description
An authenticated user can cause excessive memory usage during the processing of bitwise match expression Abstract Syntax Trees (AST). This occurs when using
$bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. Such memory pressure may lead to a loss of availability due to Out-of-Memory (OOM) conditions, where the system terminates processes because it has run out of available RAM.Recommendations
Update to version 7.0.34 or later.
Update to version 8.0.23 or later.
Update to version 8.2.9 or later.
Update to version 8.3.2 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Server
Mongodb