MongoDB Server vulnerability

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.

Published 11 Aug 2026Updated 16 Sep 20261 sources
CVSS 7.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.