Back

HIGH

Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB Server

Published Sep 8, 2026

Description

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound during query planning, and the resulting exhaustion terminates the server process. This may result in a denial of service affecting all databases served by the affected node.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Sep 8, 2026
Updated Sep 8, 2026
Reserved Aug 27, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Analyzed
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a