MongoDB Server vulnerability

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.