Out-of-Memory Failure in MongoDB Server During Expression Evaluation
CVE-2026-1849
7.1HIGH
What is CVE-2026-1849?
MongoDB Server may trigger an out-of-memory failure when processing expressions that result in deeply nested documents. This vulnerability stems from the absence of periodic checks on recursive function depth, which can lead to server crashes and degraded performance.
Affected Version(s)
MongoDB Server 8.0 < 8.0.18
MongoDB Server 7.0 < 7.0.29
MongoDB Server 8.2 < 8.2.2