Impact
The vulnerability is an uncontrolled resource consumption weakness in the request‑handling path of a MongoDB sharded‑cluster router. A client that can reach a router’s port can send connection‑monitoring parameters that force the server to consume CPU unboundedly, which can degrade performance or completely deny service to legitimate users. The flaw impacts only availability; confidentiality and integrity remain intact.
Affected Systems
The flaw resides in the sharded‑cluster router component of MongoDB Server, as documented by the JIRA ticket SERVER‑132650. The CVE does not list specific releases or affected versions, so any deployment that uses the router process in a sharded cluster without authentication may be impacted. Administrators should verify whether their router service is exposed to untrusted networks.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, classifying it as high severity. No EPSS score is available, but the lack of authentication and privileged requirements lowers the barriers to exploitation, making it a compelling target for attackers. Although it is not currently listed in the CISA KEV catalog, the impact on availability is severe, and the flaw can be triggered by any client with network access to the router port.
OpenCVE Enrichment