Description
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Server Crash)
Action: Apply Patch
AI Analysis

Impact

A $regexFindAll aggregation expression in MongoDB can crash the mongod process when the regular expression match begins in the middle of a multi-byte UTF-8 character, causing an assertion during query execution. The vulnerability is limited to server availability; it does not expose secrets or alter data integrity.

Affected Systems

Any MongoDB Server installation may be affected, as no specific version range is disclosed in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating moderate severity. An authenticated user with permission to execute aggregation pipelines can exploit it by running a $regexFindAll query that meets the trigger conditions; the EPSS score is not available and the issue is not listed in the CISA KEV catalog. While no public exploits are reported, the attack vector is straightforward for users with sufficient privileges.

Generated by OpenCVE AI on September 8, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MongoDB to the latest version or apply the vendor’s patch that fixes the $regexFindAll crash.
  • Restrict the ability to run aggregation pipelines and $regexFindAll expressions to trusted administrative roles; deny these permissions to regular application users.
  • Modify application logic to avoid using $regexFindAll or to ensure regular expressions do not start matches inside multi-byte UTF-8 characters as a temporary preventive measure.

Generated by OpenCVE AI on September 8, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Vendors & Products Mongodb mongodb

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Title $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T18:30:29.000Z

Reserved: 2026-08-27T22:50:28.074Z

Link: CVE-2026-82052

cve-icon Vulnrichment

Updated: 2026-09-08T17:55:28.390Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:32.987

Modified: 2026-09-16T20:40:42.030

Link: CVE-2026-82052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses