jira.mongodb.orgissue tracking
https://jira.mongodb.org/browse/SERVER-122449 CVE-2026-8199
HIGH
Post-auth memory exhaustion via bitwise match expressions
Record summary
CVE-2026-8199 has a selected CVSS score of 7.1 (high).
Description
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB ServerBrowse MongoDB, Inc. / MongoDB ServerDefault status: unaffected | CVE List | 7.0 to < 7.0.34 | affected |
| 8.0 to < 8.0.23 | affected | ||
| 8.2 to < 8.2.9 | affected | ||
| 8.3 to < 8.3.2 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8199