CVE-2026-8199

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-122449 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

13 May 2026, 22:31

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-122449 - () https://jira.mongodb.org/browse/SERVER-122449 - Issue Tracking, Vendor Advisory
First Time Mongodb mongodb
Mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

13 May 2026, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 04:17

Updated : 2026-05-13 22:31


NVD link : CVE-2026-8199

Mitre link : CVE-2026-8199

CVE.ORG link : CVE-2026-8199


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-1325

Improperly Controlled Sequential Memory Allocation