Impact
MongoDB Server’s query execution engine has a use‑after‑free flaw that can be triggered by an authenticated user holding read and write access when executing certain queries on time‑series collections. The flaw may cause the server to crash or expose dangling memory contents within query results, resulting in a denial of service and a possible confidentiality breach. The weakness is identified as CWE‑416.
Affected Systems
The affected product is MongoDB Server. Specific version information is not provided in the data, so all supported releases of the server are potentially impacted until a vendor‑supplied fix is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, indicating a high risk. The EPSS is reported as less than 1 %, showing a low but non‑zero likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. An attacker must possess valid credentials with read and write rights, after which they can craft a query that targets time‑series collections to trigger the use‑after‑free. Based on the description, the attack vector is authenticated remote access.
OpenCVE Enrichment