jira.mongodb.org
https://jira.mongodb.org/browse/SERVER-130117 CVE-2026-18700
MEDIUM
Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service
Record summary
CVE-2026-18700 has a selected CVSS score of 6.0 (medium).
Description
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. This could result in a server crash, leading to a denial of service.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB ServerBrowse MongoDB / MongoDB ServerDefault status: unaffected | CVE List | 8.3.0 to < 8.3.8 | affected |
| 8.0 to < 8.0.29 | affected | ||
| 7.0 to < 7.0.40 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18700