BIT-mongodb-2026-82063
Dashboard / Vulnerabilities / BIT-mongodb-2026-82063
Summary: Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service
Details: A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.
References: https://jira.mongodb.org/browse/SERVER-131870, https://nvd.nist.gov/vuln/detail/CVE-2026-82063
Affected packages
Package
Name: mongodb
Purl: pkg:bitnami/mongodb
Affected ranges
Type: SEMVER
Events:
Introduced- 7.0.0
Fixed -7.0.41
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
