Impact
The vulnerability resides in the JSON Pointer parser used by the MongoDB Server when processing $jsonSchema query filters. The parser does not limit the number of iterations or the total allocation size, allowing a specially crafted filter to consume large amounts of heap memory. When many concurrent requests contain such filters, the cumulative memory amplification can exhaust the server’s available memory, triggering the out‑of‑memory handler that terminates the mongod process. The effect is a full service interruption for all clients.
Affected Systems
MongoDB Server is affected. No specific version information is listed, so all releases of MongoDB Server may be at risk until the issue is resolved.
Risk and Exploitability
With a CVSS base score of 7.1, the vulnerability is considered medium to high risk. The EPSS score is not available, but the lack of a KEV listing suggests no known widespread exploitation yet. The attack vector is inferred to be a crafted $jsonSchema filter sent over the network; its execution requires the ability to submit a find command, which most MongoDB deployments accept from authenticated clients. Multiple concurrent malicious requests can rapidly exhaust memory, making the vulnerability highly exploitable under load.
OpenCVE Enrichment