PT-2026-48295 · Mongodb · Mongodb
CVE-2026-9749
·
Published
2026-06-09
·
Updated
2026-06-22
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MongoDB (affected versions not specified)
Description
A buffer overflow can occur during the execution of an aggregation pipeline using the internal
$exchange stage. This happens when the stage is configured with key-range partitioning and order-preserving delivery. If a single key range generates a volume of documents sufficient to fill its exchange buffer, causing many results to be routed to the same consumer, the server fails to update the internal high watermark for that key range as intended.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb