Impact
The vulnerability originates in MongoDB’s JSON Schema validation error generation routine. When a BSON document contains an array whose element field name is a malformed numeric string and violates a $jsonSchema items type constraint, the server attempts an unsafe numeric conversion on that user‑controlled field name. Because the conversion path lacks proper exception handling, an unhandled exception is raised, causing the mongod process to terminate. An attacker only needs authenticated access with readWrite privileges; the flaw is not actionable from an unauthenticated perspective. The result is a crash of the database server, leading to a denial of service. This weakness is catalogued as CWE‑248, reflecting a failure in exception handling.
Affected Systems
The affected product is MongoDB Server, as issued by MongoDB. No specific version information is listed in the CNA data, so the vulnerability likely applies to any deployment that incorporates the JSON Schema validation component present in current releases. Administrators should verify which MongoDB version is in use and whether it includes the patched logic.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity risk with a medium‑to‑high impact. The EPSS (exploit probability) score is not available, so current data do not indicate whether the vulnerability is actively exploited, but the lack of a KEV listing suggests it has not yet been observed in the wild. The attack vector requires authentication, therefore non‑credentialed exploitation is not possible; however, once legitimate readWrite access is granted, an attacker can craft a malicious BSON document and inject it through normal database operations, leading to a server crash. The likely attack path involves appending a specially‑formed document to a collection the user has write permissions for. Because the failure terminates the entire mongod process, the resulting denial of service could be pervasive across all applications relying on that database instance.
OpenCVE Enrichment