CVE-2026-82063
Dashboard / Vulnerabilities / CVE-2026-82063
Summary: Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service
Details: A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.
References: https://jira.mongodb.org/browse/SERVER-131870, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82063.json, https://nvd.nist.gov/vuln/detail/CVE-2026-82063
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 37d84072b5c5b9fd723db5fa133fb202ad2317f1
Affected versions
r7.0.35
r7.0.27-rc0
r7.0.27
r7.0.27-alpha0
r7.0.26-rc0
r7.0.26
r7.0.24-rc0
r7.0.24
r7.0.25-alpha0
r7.0.23-rc1
r7.0.23
r7.0.23-rc0
r7.0.22-rc0
r7.0.22
r7.0.21-rc0
r7.0.21
r7.0.21-alpha0
r7.0.18
r7.0.17
r7.0.16-rc1
r7.0.16-rc0
r7.0.16
r7.0.15
r7.0.15-rc1
r7.0.15-rc0
r7.0.14-rc0
r7.0.14
r7.0.13-rc1
r7.0.13
r7.0.13-rc0
r7.0.12-rc1
r7.0.12
r7.0.12-rc0
r7.0.11-rc2
r7.0.11
r7.0.11-rc1
r7.0.11-rc0
r7.0.10-rc0
r7.0.10
r7.0.9-rc1
r7.0.9
r7.0.9-rc0
r7.0.8-rc0
r7.0.8
r7.0.7-rc2
r7.0.7
r7.0.7-rc1
r7.0.7-rc0
r7.0.6-rc0
r7.0.6
r7.0.5-rc0
r7.0.5
r7.0.4-rc0
r7.0.4
r7.0.3-rc1
r7.0.3
r7.0.3-rc0
r7.0.2-rc2
r7.0.2
r7.0.2-rc1
r7.0.2-rc0
r7.0.1-rc0
r7.0.1
r7.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
