CVE-2026-1849

MEDIUM

MongoDB 7.0.0-7.0.28 - Denial of Service via Deeply Nested Document Evaluation

Title source: llm
STIX 2.1

Description

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (1)
mongodb/mongodb 7.0.0 - 7.0.29
Published Feb 10, 2026
Tracked Since Feb 18, 2026