CVE-2026-1849

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-102364 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

25 Feb 2026, 17:17

Type Values Removed Values Added
First Time Mongodb
Mongodb mongodb
Summary
  • (es) Servidor MongoDB puede experimentar un fallo por falta de memoria mientras evalúa expresiones que producen documentos profundamente anidados. El problema surge en funciones recursivas porque el servidor no comprueba periódicamente la profundidad de la expresión.
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
References () https://jira.mongodb.org/browse/SERVER-102364 - () https://jira.mongodb.org/browse/SERVER-102364 - Vendor Advisory

10 Feb 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 19:15

Updated : 2026-02-25 17:17


NVD link : CVE-2026-1849

Mitre link : CVE-2026-1849

CVE.ORG link : CVE-2026-1849


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-674

Uncontrolled Recursion