PT-2026-7434 · Mongodb+1 · Mongodb+1

Published

2026-02-10

·

Updated

2026-03-11

·

CVE-2026-1850

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MongoDB (affected versions not specified)
Description Complex queries can lead to excessive memory consumption within the MongoDB Query Planner, potentially causing an Out-Of-Memory crash. An authorized user can disrupt the MongoDB server by submitting specific complex queries due to boolean expression simplification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-01863
BIT-MONGODB-2026-1850
CVE-2026-1850

Affected Products

Mongodb
Red Os