Executive brief
A security vulnerability exists in MongoDB's Field-Level Encryption (FLE) component, which is used to protect sensitive data by encrypting it before it reaches the database. An attacker with the ability to influence database queries could potentially cause a system crash or unauthorized data access. This affects organizations using client-side encryption features in specific versions of MongoDB.
Technical details
A use-after-free (CWE-416) vulnerability was identified in the MongoDB Field-Level Encryption (FLE) query analysis component. The flaw is triggered when calling 'replaceEncryptedFieldsInFilter' with positional projections, leading to memory corruption. An attacker with network access and low privileges who can control the structure of FLE-related queries can exploit this to cause a denial-of-service (crash) or potentially achieve limited data exposure. The issue affects the mongocryptd and crypt_shared components. Patches have been released in versions 7.0.34, 8.0.23, 8.2.9, and 8.3.2.
Affected products
- MongoDB MongoDB Server (mongocryptd) 7.0.0 to 7.0.33, 8.0.0 to 8.0.22, 8.2.0 to 8.2.8, 8.3.0 to 8.3.1
Timeline
- 2026-03-18: other: Issue reported internally/created in Jira
- 2026-05-12: patched: Issue resolved in development tracking
- 2026-05-13: disclosed: Public disclosure of CVE-2026-8201