Stack memory disclosure in filemd5 command
CVE-2026-9754
7.1HIGH
What is CVE-2026-9754?
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
Affected Version(s)
MongoDB 8.3.0 < 8.3.3
MongoDB 8.2.0 < 8.2.10