CVE-2026-9740
7.5 HIGHA vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a special...
Published: 2026-06-09 · Last updated: 2026-06-09
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-674
Description
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-46373 — SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code (7.5 HIGH)
- CVE-2026-49847 — FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implem... (7.5 HIGH)
- CVE-2026-49941 — Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses (7.5 HIGH)
- CVE-2026-47706 — Strawberry GraphQL is a library for creating GraphQL APIs (5.3 MEDIUM)
- CVE-2026-47320 — Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversiz... (6.1 MEDIUM)