Back

HIGH

Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.

Published Jun 9, 2026

Description

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mongodb
Published Jun 9, 2026
Updated Jun 10, 2026
Reserved May 27, 2026
CISA Vulnrichment
Updated Jun 10, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a