CVE-2026-8201

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-122032 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

13 May 2026, 22:50

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-122032 - () https://jira.mongodb.org/browse/SERVER-122032 - Issue Tracking, Vendor Advisory
First Time Mongodb mongodb
Mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

13 May 2026, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 04:17

Updated : 2026-05-13 22:50


NVD link : CVE-2026-8201

Mitre link : CVE-2026-8201

CVE.ORG link : CVE-2026-8201


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-416

Use After Free