Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server

CVE Details

Basic Information

Title Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server
Type cve
Published 2025-06-26T14:00:22.802Z
Last Seen

Product Information

Vendor MongoDB Inc
Product MongoDB Server
Version 6.0

CVSS Information

Base Score 5.0 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description An authenticated user can cause a MongoDB Server crash or unexpected behavior by executing specific aggregation operations with the SBE engine enabled, potentially leading to service disruption.
AI Severity Medium
Vendor MongoDB Inc
Product MongoDB Server
Affected Version 6.0.0-6.0.21, 7.0.0-7.0.17, 8.0.0-8.0.4

Affected Products

  • MongoDB Inc MongoDB Server 6.0
  • MongoDB Inc MongoDB Server 7.0
  • MongoDB Inc MongoDB Server 8.0

Additional Information

CVE List
CWE List CWE-416
Bulletin Family

Description

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server.
The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.