Executive brief
MongoDB Server contains a flaw in its geospatial data validation logic that can be triggered by authenticated users with write access. When concurrent write operations target a collection with a specific type of validator, a memory reference can be used after it has been freed, causing the server to crash and becoming unavailable to legitimate users.
Technical details
A heap use-after-free vulnerability exists in MongoDB Server's collection validation logic, specifically in the handling of geospatial (polygon) validators. The flaw is triggered when concurrent write operations are performed against a collection configured with a big polygon validator, causing an internal reference to be accessed after the underlying memory has been freed. This is a classic use-after-free memory safety issue that can result in a server crash (denial of service). The vulnerability requires authentication with write privileges and is fully patched in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, and 9.0.0-rc2 or later.
Affected products
- MongoDB Server before 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Patches released for versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2