Regex Vulnerability in MongoDB Server by MongoDB Inc.
CVE-2026-82052

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82052?

An authenticated user can exploit the $regexFindAll expression in MongoDB's aggregation pipeline to cause a server crash. This occurs when the regex match operation is initiated in the midst of a multi-code-unit character, which leads to an assertion failure during query execution. It is crucial for users to understand the risks and apply patches to prevent potential disruptions.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0 < 8.0.30

MongoDB Server 7.0 < 7.0.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.