Out-of-bounds read in MongoDB Server - CVE-2026-18694
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and disclose limited process memory.
The vulnerability exists due to out-of-bounds read in MongoDB Server geospatial query processing when handling subsequent queries against stored malformed geometry data. A remote user can store specially crafted geometry data to cause a denial of service and disclose limited process memory.
Exploitation requires write privileges to store malformed geometry data before it is later queried.