CVE 6.1 MEDIUM

Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields_CVE-2026-8201

6.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:N/SA:N

Description

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query.

This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Basic Information

ID CVE-2026-8201
Source mongodb
Published May 13, 2026 at 00:12

Affected Product

Vendor MongoDB, Inc.
Product MongoDB Server
Version 7.0
Affected Versions MongoDB, Inc. MongoDB Server 7.0
MongoDB, Inc. MongoDB Server 8.0
MongoDB, Inc. MongoDB Server 8.2
MongoDB, Inc. MongoDB Server 8.3

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.