Memory Amplification Vulnerability in MongoDB Server's JSON Pointer Parser
CVE-2026-82054

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
8 September 2026

What is CVE-2026-82054?

A security issue has been identified in the MongoDB server due to its JSON Pointer parser utilized during the processing of $jsonSchema query filters. When a find command incorporates a carefully constructed $jsonSchema filter, the parser fails to exercise sufficient constraints on iteration counts and total allocation sizes. This oversight can lead to severe memory amplification, particularly under heavy concurrent request loads. Consequently, the cumulative memory demands might surpass available heap memory, leading the server’s out-of-memory handler to terminate the mongod process, which results in service denial for all connected clients.

Affected Version(s)

MongoDB Server 8.3.0 < 8.3.9

MongoDB Server 8.0.0 < 8.0.30

MongoDB Server 7.0.0 < 7.0.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.