Impact
An integer overflow in MongoDB Server's query planning component permits an authenticated user with ordinary database‑level read/write privileges to exceed an internal resource limit. Submitting a specially crafted query leads the server to allocate memory without bound during planning, culminating in process termination. The resulting denial of service affects all databases served by the compromised node.
Affected Systems
MongoDB Server. No specific product version is listed in the current data.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1 and is not listed in the CISA KEV catalog, with no EPSS score available. Attack is carried out by an already authenticated user; the attacker must supply a crafted query to trigger the overflow. The impact is a system‑wide denial of service, although no remote code execution or privilege escalation is involved. Risk exists primarily for workloads exposed to authenticated users who have write access to the database.
OpenCVE Enrichment