CVE-2026-4147

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-119317 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha0:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha1:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha2:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha3:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:rc1:*:*:-:*:*:*

History

10 Apr 2026, 17:40

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-119317 - () https://jira.mongodb.org/browse/SERVER-119317 - Patch, Vendor Advisory
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha3:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha1:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha2:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:rc1:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:8.3.0:alpha0:*:*:-:*:*:*
First Time Mongodb
Mongodb mongodb
CWE CWE-908

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Un usuario autenticado con el rol de lectura puede leer cantidades limitadas de memoria de pila no inicializada a través de invocaciones especialmente diseñadas del comando filemd5.

17 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 16:16

Updated : 2026-04-10 17:40


NVD link : CVE-2026-4147

Mitre link : CVE-2026-4147

CVE.ORG link : CVE-2026-4147


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-457

Use of Uninitialized Variable

CWE-908

Use of Uninitialized Resource