CVE-2026-82056

⚪ Do wiadomości

Warunek wyścigu w MongoDB może prowadzić do awarii serwera i odmowy usługi.

CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
mongodb
Opis źródłowy (NVD)

A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-08 17:18:33 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:35:00 UTC
Referencje