Impact
A $regexFindAll aggregation expression in MongoDB can crash the mongod process when the regular expression match begins in the middle of a multi-byte UTF-8 character, causing an assertion during query execution. The vulnerability is limited to server availability; it does not expose secrets or alter data integrity.
Affected Systems
Any MongoDB Server installation may be affected, as no specific version range is disclosed in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating moderate severity. An authenticated user with permission to execute aggregation pipelines can exploit it by running a $regexFindAll query that meets the trigger conditions; the EPSS score is not available and the issue is not listed in the CISA KEV catalog. While no public exploits are reported, the attack vector is straightforward for users with sufficient privileges.
OpenCVE Enrichment