A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command include…

cve CVE-2026-82054 1 source, 1 claim · Watch

NVD writes:
A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients. the claim
Severity
MEDIUM NVD
CVSS
6.5 NVD
Fixed in
8.3.9, 8.0.30, 7.0.41 NVD
Vendor
MongoDB NVD
Product
MongoDB Server NVD
CWE
CWE-770 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-09-08first spoke of it: A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients.NVD

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients.

What it is to other things

affectsmongodb/mongodb
NVD
made_bymongodb
NVD

In words only, so not counted until a person confirms one:

affectsmongodb/mongodb_server
NVD says “MongoDB · MongoDB Server”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4
cvss4
NVD7.1
receipt
Source
NVD
Its words
7.1
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTC7.1
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-770
receipt
Source
NVD
Its words
CWE-770
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-770
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Fixed in
fixed_in
NVD8.3.9, 8.0.30, 7.0.41
receipt
Source
NVD
Its words
8.3.9, 8.0.30, 7.0.41
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTC8.3.9, 8.0.30, 7.0.41
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDMongoDB Server
receipt
Source
NVD
Its words
MongoDB Server
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCMongoDB Server
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDMongoDB
receipt
Source
NVD
Its words
MongoDB
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCMongoDB
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "MongoDB Server",
            "vendor": "MongoDB",
            "versions": [
              {
                "lessThan": "8.3.9",
                "status": "affected",
                "version": "8.3.0",
                "versionType": "semver"
              },
              {
                "lessThan": "8.0.30",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.41",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cna@mongodb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A5FF36EB-FE0C-4E45-89A1-B1AFE6B6066E",
                "versionEndExcluding": "7.0.41",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1453A331-791B-4263-8171-B561879F033F",
                "versionEndExcluding": "8.0.30",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7BCD6B05-9FD5-4283-A2AC-8B625425597F",
                "versionEndIncluding": "8.2.12",
                "versionStartIncluding": "8.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1A52BC12-2A23-4B10-9014-F97AD555CEC7",
                "versionEndExcluding": "8.3.9",
                "versionStartIncluding": "8.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "0FB52026-6C88-4401-84B5-3A070F0906D4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*",
                "matchCriteriaId": "8D32A105-731C-493E-8CBF-639204CDAC7C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mongodb:mongodb:9.1.0:alpha0:*:*:-:-:*:*",
                "matchCriteriaId": "D56E512D-83F8-4D51-8690-E92F6A006822",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients."
      }
    ],
    "id": "CVE-2026-82054",
    "lastModified": "2026-09-16T20:40:15.627",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@mongodb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-82054",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-08T17:56:10.734402Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-08T17:18:33.280",
    "references": [
      {
        "source": "cna@mongodb.com",
        "tags": [
          "Vendor Advisory",
          "Issue Tracking"
        ],
        "url": "https://jira.mongodb.org/browse/SERVER-130901"
      }
    ],
    "sourceIdentifier": "cna@mongodb.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "cna@mongodb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or total allocation size, resulting in significant memory amplification. Under concurrent request load, the cumulative memory consumption can exhaust available heap memory, causing the server's out-of-memory handler to terminate the mongod process and deny service to all connected clients.
zetlyn/cve-nvd · 2026-09-08
automatable no cvss 6.5 cvss4 7.1 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H cwe CWE-770 exploitation none fixed_in 8.3.9, 8.0.30, 7.0.41 product MongoDB Server severity MEDIUM status Analyzed technical_impact partial vendor MongoDB source