Executive brief
MongoDB Server is a widely-used document database engine. An authenticated attacker can submit a specially crafted query that causes the query planning component to crash, resulting in denial of service and making the database temporarily unavailable. The attack requires only standard read/write database privileges and no special configuration.
Technical details
An integer overflow vulnerability exists in MongoDB's QueryPlannerAnalysis::explodeForSort() function in src/mongo/db/query/planner_analysis.cpp. When processing a find().sort() query with multiple $in predicates containing large numbers of values, the planner multiplies the point-interval counts without overflow checking. With eight $in predicates of 256 values each, the calculation 256^8 wraps to 0 on 64-bit systems, bypassing the maxScansToExplode safety guard. The planner then proceeds into Cartesian product materialization, causing unbounded memory consumption and process termination. Attack requires authenticated database access and a collection with a suitable compound index; the fix is available in MongoDB 7.0.41, 8.0.30, 8.2.13, 8.3.9, and 9.0.0-rc2 or later.
Affected products
- MongoDB MongoDB Server 7.0.0 through 7.0.40, 8.0.0 through 8.0.29, 8.2.0 through 8.2.6, 8.3.0 through 8.3.8, 9.0.0-rc0 and rc1
Timeline
- 2026-09-08: disclosed: Public disclosure via NVD
- 2026-09-08: patched: Patched in versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, 9.0.0-rc2 and later