Race Condition Vulnerability in MongoDB Server Text Index Query Parsing
CVE-2026-82056
6MEDIUM
What is CVE-2026-82056?
A race condition in the MongoDB server's text index query parsing can lead to a heap use-after-free read. This occurs during specific concurrent operations related to text-search and index management. When an authenticated user with readWrite privileges executes these operations, there's a risk of accessing freed internal text index metadata, which may cause the MongoDB server to crash. Consequently, this results in a denial of service for all connected clients, impacting overall system availability.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.9
MongoDB Server 8.0.0 < 8.0.30
MongoDB Server 7.0.0 < 7.0.41