Back

HIGH

Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos

Published Aug 11, 2026

Description

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a