HarborGuard / CVE
Back to search
HIGHCVE-2026-8199Published Modified CNA mongodb

CVE-2026-8199: Post-auth memory exhaustion via bitwise match expressions

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
7.0.34
Affected Products
1

Fix available

7.0.348.0.238.2.98.3.2
Affected packages
  • MongoDB, Inc. / MongoDB Server
    < 7.0.34 (from 7.0) · < 8.0.23 (from 8.0) · < 8.2.9 (from 8.2) · < 8.3.2 (from 8.3)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-8199: Post-auth memory exhaustion via bitwise match expressions | HarborGuard CVE