NULL pointer dereference in MongoDB Server - CVE-2026-8063
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to null pointer dereference in the aggregation pipeline inspection logic for $rankFusion and $scoreFusion when resolving a view with an empty input pipeline array. A remote user can run $rankFusion or $scoreFusion with an empty pipeline on a view to cause a denial of service.