Impact
A race condition in MongoDB Server's text index query parsing can trigger a heap use-after-free read when handling upsert retry paths. The flaw surfaces during concurrent index lifecycle operations, causing a raw pointer to internal text index metadata to be dereferenced after the underlying structures have been freed. An authenticated user with readWrite privileges can exploit this to crash the server, resulting in a denial of service for all connected clients. This vulnerability falls under CWE‑416 and directly compromises availability rather than confidentiality or integrity.
Affected Systems
MongoDB Server is the affected product. The specific impacted versions are not listed in the advisory, so any release prior to the fix that implements proper synchronization in text index query parsing could be vulnerable.
Risk and Exploitability
The CVSS score of 6 denotes a moderate severity. EPSS information is not available, so the current exploitation probability is unknown, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated user with readWrite access to a database that uses text indexes; the attacker must also trigger concurrent text search and index management operations. If the vulnerability is successfully triggered, the server will crash and deny service to all clients. This poses a moderate risk to availability for systems that lack timely patches and proper privilege controls.
OpenCVE Enrichment