Description
A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geometry parsing can leave an internal object in an invalid, partially initialized state. During subsequent index key generation, access to this improperly initialized object results in a null pointer dereference that terminates the mongod process. An authenticated user with write access can use this to cause a denial of service.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A null‑pointer dereference occurs during 2dsphere index key generation when a special GeoJSON object is inserted into a collection that has a 2dsphere index. The vulnerability leaves an internal object in a partially initialized state and causes the mongod process to terminate. An authenticated user with write access can exploit this to take the database down, resulting in a denial of service.

Affected Systems

MongoDB Server deployments that use 2dsphere indices are affected. Version information is not provided in the advisory; any release that includes this index code prior to a fix is vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1. No EPSS score is available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with write permissions. If an attacker compromises such an account or a legitimate user intentionally crafts the payload, the database can be forced to crash, disrupting service availability.

Generated by OpenCVE AI on September 8, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a MongoDB Server version that fixes the 2dsphere index key generation bug.
  • If an upgrade is not immediately possible, restrict write access to collections that use 2dsphere indexes or temporarily remove those indexes until a patch is applied.
  • Validate and sanitize GeoJSON documents before insertion to ensure geometries are consistent and fully initialized, guarding against null references.
  • Monitor mongod logs for unexpected crashes and enable automatic restart mechanisms to maintain availability.

Generated by OpenCVE AI on September 8, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geometry parsing can leave an internal object in an invalid, partially initialized state. During subsequent index key generation, access to this improperly initialized object results in a null pointer dereference that terminates the mongod process. An authenticated user with write access can use this to cause a denial of service.
Title Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of Service
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:56:59.707Z

Reserved: 2026-08-27T22:50:59.592Z

Link: CVE-2026-82055

cve-icon Vulnrichment

Updated: 2026-09-08T17:56:36.110Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:33.410

Modified: 2026-09-16T20:35:09.137

Link: CVE-2026-82055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses