An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM.
This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-122449 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 May 2026, 22:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jira.mongodb.org/browse/SERVER-122449 - Issue Tracking, Vendor Advisory | |
| First Time |
Mongodb mongodb
Mongodb |
|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
13 May 2026, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 04:17
Updated : 2026-05-13 22:31
NVD link : CVE-2026-8199
Mitre link : CVE-2026-8199
CVE.ORG link : CVE-2026-8199
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-1325
Improperly Controlled Sequential Memory Allocation
