CVE-2026-8199
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-1325
- Published
- 2026-05-13
- Last modified
- 2026-05-13
Affected products
- MongoDB, Inc. MongoDB Server
- MongoDB, Inc. MongoDB Server
- MongoDB, Inc. MongoDB Server
- MongoDB, Inc. MongoDB Server
Weakness type
Related vulnerabilities
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark