MongoDB Server vulnerability

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 8.7

Source timeline

CVE record published by NVDView source ↗