CVE-2026-1849

MEDIUM

MongoDB Server - Memory Corruption

Title source: llm
STIX 2.1

Description

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (1)
mongodb/mongodb 7.0.0 - 7.0.29
Published Feb 10, 2026
Tracked Since Feb 18, 2026