Junglewise Threat Intelligence

CVE-2026-82058: MongoDB JSON Schema validation error generation denial of service

CVE-2026-82058 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: MongoDB Server. Vendors: MongoDB.

Executive brief

MongoDB, a widely-used NoSQL database, contains a flaw in its JSON Schema validation error handling that allows authenticated database users with readWrite permissions to crash the database server. An attacker can craft a malformed BSON document with a specially-formatted array field name to trigger the vulnerability, causing the mongod process to terminate and resulting in service unavailability for all users and applications relying on that database instance.

Technical details

The vulnerability is a denial-of-service condition in MongoDB's JSON Schema validation error generation code, specifically in the generateJSONSchemaArraySingleSchemaError method. When validating a BSON document against a $jsonSchema constraint on array items, the code uses std::strtoll to convert array element field names to numeric indices but does not properly handle exceptions that can be thrown by this function on malformed input. The wire protocol validation layer does not enforce that array element field names are valid numeric indices, allowing an authenticated attacker with readWrite database privileges to submit a specially-crafted BSON document that triggers an uncaught std::exception, causing the mongod process to terminate. The vulnerability requires prior database authentication and explicit schema validation constraints to exploit. MongoDB has released patches in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, and 9.1.0-rc0 and later.

Affected products

  • MongoDB MongoDB Server before 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0

Timeline

  • 2026-09-08: disclosed: CVE-2026-82058 published
  • 2026-09-08: patched: Fix released in MongoDB 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2, 9.1.0-rc0 and later versions

References

Related threats