CVE-2026-1849

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/02/2026
Last modified:
25/02/2026

Description

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.29 (excluding)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.18 (excluding)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.2 (excluding)


References to Advisories, Solutions, and Tools