Impact
The vulnerability is a heap out‑of‑bounds read in the query planning component of MongoDB Server. An authenticated user who has read and write access to a database can craft special query operations that cause the server to read memory beyond the bounds of a buffer. The memory contents can then appear, at least in part, in the diagnostic query statistics output, exposing potentially sensitive data. This defect is classified as CWE‑125.
Affected Systems
MongoDB Server is affected. No specific product versions are listed in the data, so any installation running the MongoDB Server component before the fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates the susceptibility can lead to partial data exposure but does not imply remote code execution. The EPSS score is unavailable, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with database read/write privileges, so attack surface is limited to trusted users or compromised accounts. The exploit might be constrained by the need for diagnostic query statistics to be enabled, which can be turned off by administrators.
OpenCVE Enrichment