Impact
A use‑after‑free flaw in MongoDB Server’s cursor management component allows an authenticated user, under precise timing during cursor operations, to cause the database to crash during cleanup of a stale pointer. The vulnerability results in a denial of service, disrupting database availability without exposing data or permitting unauthorized code execution.
Affected Systems
MongoDB Server installations are affected. No specific version range is provided, so the issue may impact any release of the server component until a patch is applied.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity vulnerability. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires that the user be authenticated and that a timing window during cursor activity be achieved, which reduces the attack surface but still permits a DoS if the conditions are met. Overall risk is moderate; organizations should treat this as a medium‑to‑high priority if the affected database provides critical services.
OpenCVE Enrichment