CVE-2025-11979Medium· 5.3▾ SunlitAn authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Oct 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to 8.0.15, and MongoDB Server version 8.2.0.
mongodb >= 7.0.0, < 7.0.25mongodb >= 8.0.0, < 8.0.15Upgrade past the affected range:
mongodb 8.0.15Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82056Medium· 5.3A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths
CVE-2026-82061High· 8.1A use-after-free security issue exists in the server's query execution memory tracking subsystem
CVE-2026-82063Medium· 5.3A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service
CVE-2026-18711High· 7.1An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries again…
CVE-2026-18706Medium· 6.6An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed
CVE-2026-18700Medium· 6.5An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a coll…