Impact
A use‑after‑free vulnerability exists in MongoDB Server's query execution memory tracking subsystem. An authenticated user with read privileges can send a sequence of standard database commands that trigger a write to freed heap memory, causing the server to crash or potentially corrupt memory. This flaw is a classic use‑after‑free (CWE‑416) and requires no user interaction beyond the database commands.
Affected Systems
MongoDB Server. Specific affected version information is not publicly disclosed in the advisory.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate severity, and the EPSS score is not available. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires an authenticated account with read permissions and the ability to execute custom database commands, which could be achieved by an internal user or a compromised account. Once triggered, the server process will crash, resulting in denial of service, and there is a potential for memory corruption that could affect other system components.
OpenCVE Enrichment