Impact
An authenticated user with write privileges to MongoDB Server can insert malformed geometry data that is later processed by the geospatial query engine. During processing, the server may access memory beyond its bounds, leading to an out-of-bounds read. This can cause the server to crash, resulting in a denial of service, and may expose a limited portion of server process memory. The weakness is aligned with CWE‑125, which denotes out-of-bounds memory reads.
Affected Systems
MongoDB Server is affected. The vulnerability impacts versions prior to the fix for ticket SERVER‑130188. Specific version ranges are not disclosed in the advisory, so all installations of MongoDB Server that have not applied the latest security patches are susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while an EPSS score of less than 1 % indicates a very low probability of exploitation in the wild at the time of analysis. Because the vulnerability requires authenticated write access, attackers must compromise a legitimate account; otherwise, the attack is not feasible. The absence from the CISA KEV list suggests that targeted exploitation is not yet known, but the potential for denial of service and memory disclosure still warrants prompt action.
OpenCVE Enrichment