HIGH
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
Published Jun 9, 2026
8.7
HIGHCVSS 4.0
EPSS 0.53%
Description
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking.
Affected products
-
Affected
- ≥ 7.0.0, < 7.0.35
- ≥ 8.0.0, < 8.0.24
- ≥ 8.2.0, < 8.2.10
- ≥ 8.3.0, < 8.3.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MongoDB | MongoDB Server | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35857 Advisory
- https://jira.mongodb.org/browse/SERVER-125063 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35857 | Advisory | |
| https://jira.mongodb.org/browse/SERVER-125063 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Jun 9, 2026
Updated Jun 10, 2026
Reserved May 27, 2026
Link CVE-2026-9740
CISA Vulnrichment
Updated Jun 10, 2026
Red Hat
No data
GitHub
No data