Impact
A null‑pointer dereference occurs during 2dsphere index key generation when a special GeoJSON object is inserted into a collection that has a 2dsphere index. The vulnerability leaves an internal object in a partially initialized state and causes the mongod process to terminate. An authenticated user with write access can exploit this to take the database down, resulting in a denial of service.
Affected Systems
MongoDB Server deployments that use 2dsphere indices are affected. Version information is not provided in the advisory; any release that includes this index code prior to a fix is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1. No EPSS score is available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with write permissions. If an attacker compromises such an account or a legitimate user intentionally crafts the payload, the database can be forced to crash, disrupting service availability.
OpenCVE Enrichment