Use-after-free in MongoDB Server - CVE-2026-8201
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and disclose sensitive information.
The vulnerability exists due to use-after-free in the Field-Level Encryption (FLE) query analysis component when processing positional projections on encrypted fields in FLE-related queries. A remote user can send a specially crafted FLE-related query to cause a denial of service and disclose sensitive information.
The issue affects client-side uses of mongocryptd and crypt_shared, and exploitation requires control over the structure of a client's FLE-related query.