Junglewise Threat Intelligence

CVE-2026-18700: MongoDB Server heap use-after-free in geospatial validation

CVE-2026-18700 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB Server contains a flaw in its geospatial data validation logic that can be triggered by authenticated users with write access. When concurrent write operations target a collection with a specific type of validator, a memory reference can be used after it has been freed, causing the server to crash and becoming unavailable to legitimate users.

Technical details

A heap use-after-free vulnerability exists in MongoDB Server's collection validation logic, specifically in the handling of geospatial (polygon) validators. The flaw is triggered when concurrent write operations are performed against a collection configured with a big polygon validator, causing an internal reference to be accessed after the underlying memory has been freed. This is a classic use-after-free memory safety issue that can result in a server crash (denial of service). The vulnerability requires authentication with write privileges and is fully patched in versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, and 9.0.0-rc2 or later.

Affected products

  • MongoDB Server before 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Patches released for versions 7.0.40, 8.0.29, 8.2.13, 8.3.8, 9.0.0-rc2

References