Executive brief
Oracle REST Data Services, a tool that enables developers to use HTTP and REST with Oracle databases, contains a vulnerability in its Mongo API component. An unauthenticated attacker can remotely exploit this flaw to cause the service to hang or crash repeatedly. This results in a complete denial of service, preventing legitimate users and applications from accessing the database via the REST interface.
Technical details
A vulnerability in the Mongoapi component of Oracle REST Data Services (ORDS) allows for a complete denial of service. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the ORDS instance. The vulnerability affects versions 24.2.0 through 26.1.0. While specific root cause details (such as the exact CWE) are not provided in the advisory, the CVSS vector indicates a high availability impact with low attack complexity and no required privileges.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: advisory: Oracle published the security alert and NVD record was created.